Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency org.apache.logging.log4j:log4j-core has multiple CVE against it #11

Open
jairmyree opened this issue Feb 16, 2023 · 0 comments

Comments

@jairmyree
Copy link

The latest release of classif takes dependency on org.apache.logging.log4j:log4j-core:jar:2.11.2 which has multiple direct CVEs against it.
This CVEs are being passed into the latest release of org.revapi:revapi-java (version 0.28.0).
Please release a version with the dependency org.apache.logging.log4j:log4j-core upgraded to version 2.17.1 or greater where these direct CVEs have been resolved.

I'm linking here the issue that I've opened with revapi as well.
revapi/revapi#284

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant