-
Notifications
You must be signed in to change notification settings - Fork 669
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update log4j version to 2.17.1 #891
base: master
Are you sure you want to change the base?
Conversation
Fix securty issues https://nvd.nist.gov/vuln/detail/CVE-2021-44832
@technoLord Any ETA on this release? |
I opened an issue #893 to request a new release with this fix included. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I believe
<bouncycastle.version>1.58</bouncycastle.version> (line 80)
needs to be
<bouncycastle.version>1.6</bouncycastle.version>
as well since bouncycastle 1.58 uses an older log4j
Is there any update on this? when this shall be released. |
looks like this project is abandoned |
Yeah, I figured as much. If anyone ever picks it up this needs to be fixed. Until then if anyone is using this dependency, you will either need to fork and patch it locally or force maven to use only newer versions of log4j |
Fix securty issues https://nvd.nist.gov/vuln/detail/CVE-2021-44832