Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump log4j2 version for cve-2021-44228 #604

Merged
merged 1 commit into from
Jan 21, 2022
Merged

Bump log4j2 version for cve-2021-44228 #604

merged 1 commit into from
Jan 21, 2022

Conversation

eltonlaw
Copy link
Contributor

Addressing vulnerability to remote code execution via log4j2 JNDI lookup: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228

From version 2.16.0, this functionality has been completely removed

@eltonlaw eltonlaw changed the title Bump log4j2 version for cve-2021-44228 [vulnerability] Bump log4j2 version for cve-2021-44228 Dec 16, 2021
@dakrone
Copy link
Owner

dakrone commented Dec 22, 2021

This should probably upgrade to 2.17.0 since another release was created to address the DOS issue.

@eltonlaw
Copy link
Contributor Author

@dakrone dakrone changed the title [vulnerability] Bump log4j2 version for cve-2021-44228 Bump log4j2 version for cve-2021-44228 Jan 21, 2022
@dakrone dakrone merged commit c37f265 into dakrone:3.x Jan 21, 2022
@dakrone
Copy link
Owner

dakrone commented Jan 21, 2022

Merged, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants