Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update log4j-core and log4j-api dependencies to 2.16.0 #290

Closed
wants to merge 2 commits into from

Conversation

tomeara
Copy link

@tomeara tomeara commented Dec 14, 2021

Issue #, if available:
#289

Description of changes:
Mitigates against additional log4shell scenarios by upgrading log4j dependencies to 2.16.0

  • Update log4j-core and log4j-api dependencies to 2.16.0
  • Stage update to aws-lambda-java-log4j2 version 1.3.1

GitHub Advisory

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@tomeara tomeara changed the title upgrades log4j to 2.16.0 Update log4j-core and log4j-api dependencies to 2.16.0 Dec 14, 2021
@ericlink
Copy link

This is now urgent, 2.16 is now required to remediate: https://logging.apache.org/log4j/2.x/security.html

@baldram
Copy link
Contributor

baldram commented Dec 15, 2021

I prepared a change late evening yesterday (I did not see this change then) but pushed now in the morning.

A previous fix was about changing minor not patch version.
If for consistency, the AWS team would like to mark this release as 1.4.0, here is my PR fixing the same problem:
#293
Otherwise it might be closed.

@msailes
Copy link
Collaborator

msailes commented Dec 15, 2021

Thanks for the PR.

Duplicate of #293

@msailes msailes closed this Dec 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants