-
-
Notifications
You must be signed in to change notification settings - Fork 423
CVE-2020-9488: log4j 2.11.0 #589
Copy link
Copy link
Closed
Description
Shadow bundles log4j 2.11.0 which is has a known security vulnerability. See http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9488. It would be great if you can possibly update the version of log4j in use.
Shadow Version
5.2.0 & 6.0.0
Gradle Version
All
Actual Behavior
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
