Hello, Since Clearml-Server Uses Elasticsearch, Is There Any Security Issue Related To This

As stated there:
We've confirmed that the Security Manager mitigates the remote code execution attack in Elasticsearch 6 and 7;Which basically means ClearML-Server is not affected. We will include the -Dlog4j2.formatMsgNoLookups=true JVM flag (just to be on the safe side) in the coming release (and users can also do it right now in their own docker-compose, of course)

Posted 3 years ago
0 Answers
3 years ago
2 years ago