You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is not reflected in the GHSA affected range, and raises False Positive on dependency scanning.
I have opened this PR on GHSA but haven't got a response yet - could someone please confirm this? github/advisory-database#8692
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Hi log4j team -
I was invetigating this CVE's affected scope, and I've noticed that the fix was backported to 2.3.x branch.
Log4j advisory reports its fixed in 2.3.1. https://logging.apache.org/security.html#CVE-2021-45046
Also reflected in changelog rel/2.3...rel/2.3.1
This is not reflected in the GHSA affected range, and raises False Positive on dependency scanning.
I have opened this PR on GHSA but haven't got a response yet - could someone please confirm this?
github/advisory-database#8692
I appreciate you help, thank you!
All reactions