Skip to content

Bump log4j to 2.17.0#342

Merged
ok2c merged 1 commit intoapache:masterfrom
pcoelho-coveo:master
Dec 23, 2021
Merged

Bump log4j to 2.17.0#342
ok2c merged 1 commit intoapache:masterfrom
pcoelho-coveo:master

Conversation

@pcoelho-coveo
Copy link
Contributor

Version 2.17.0 fixes the issue CVE-2021-45105

Copy link
Member

@garydgregory garydgregory left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Simple enough ;-)

@ok2c ok2c merged commit d649cba into apache:master Dec 23, 2021
@pcoelho-coveo
Copy link
Contributor Author

Hi @garydgregory, do we have a date to the next release? My team would love to upgrade our current version to the one that has this fix.

Thanks.

@ok2c
Copy link
Member

ok2c commented Jan 5, 2022

@pcoelho-coveo Why would you need this fix? HttpClient runtime does not depend on log4j2-core.

@pcoelho-coveo
Copy link
Contributor Author

Yeah I am aware of that. We have an internal tool that scan our dependencies and it is currently flagging our http client dependency, even though the log4j is used only on the tests and is not included on our classpath.

@ok2c
Copy link
Member

ok2c commented Jan 5, 2022

@pcoelho-coveo You should consider fixing the tool.

@michael-o
Copy link
Member

michael-o commented Jan 5, 2022

@pcoelho-coveo You should consider fixing the tool.

Same shit from commercial scanners over and over again. A colleague of mine was requested to patch the following file: log4j-....pom

@ok2c If course we can fix that, the release manager receives a payment for the release from @pcoelho-coveo employer.

@garydgregory
Copy link
Member

Hi @garydgregory, do we have a date to the next release? My team would love to upgrade our current version to the one that has this fix.

Thanks.

You should use 2.17.1, it's been available for a while now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants