Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade log4j-api to 2.8.2 as CVE-2017-5645 #99

Closed
wants to merge 1 commit into from

Commits on Nov 19, 2018

  1. Upgrade log4j-api to 2.8.2 as CVE-2017-5645

    Vulnerability CVE-2017-5645 requires Apache Log4j 2.x upgraded to version to or after 2.8.2
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5645
    In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
    caixiangibm committed Nov 19, 2018
    Copy the full SHA
    1f3df88 View commit details
    Browse the repository at this point in the history