Skip to content

CVE-2020-9488: log4j 2.11.0 #589

@ysb33r

Description

@ysb33r

Shadow bundles log4j 2.11.0 which is has a known security vulnerability. See http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9488. It would be great if you can possibly update the version of log4j in use.

Shadow Version

5.2.0 & 6.0.0

Gradle Version

All

Actual Behavior

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions