Skip to content

Conversation

@julianladisch
Copy link
Contributor

https://folio-org.atlassian.net/browse/OKAPI-1238

Upgrade log4j from 2.25.1 to 2.25.3 to fix this vulnerability:

  • CVE-2025-68161 Missing validation of hostname in TLS certificate when using SocketAppender

FOLIO logs to STDOUT and doesn’t use SocketAppender, however, other uses of Okapi may use SocketAppender and we want to provide a secure version of the log4j dependency Okapi ships with.

…ion CVE-2025-68161

https://folio-org.atlassian.net/browse/OKAPI-1238

Upgrade log4j from 2.25.1 to 2.25.3 to fix this vulnerability:

* CVE-2025-68161 Missing validation of hostname in TLS certificate when using SocketAppender

FOLIO logs to STDOUT and doesn’t use SocketAppender, however, other uses of Okapi may use SocketAppender and we want to provide a secure version of the log4j dependency Okapi ships with.
@sonarqubecloud
Copy link

@julianladisch julianladisch merged commit 8a386ed into master Jan 12, 2026
5 checks passed
@julianladisch julianladisch deleted the OKAPI-1238 branch January 12, 2026 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants