Skip to content

Bump log4j2 version for cve-2021-44228#604

Merged
dakrone merged 1 commit intodakrone:3.xfrom
eltonlaw:3.x
Jan 21, 2022
Merged

Bump log4j2 version for cve-2021-44228#604
dakrone merged 1 commit intodakrone:3.xfrom
eltonlaw:3.x

Conversation

@eltonlaw
Copy link
Contributor

Addressing vulnerability to remote code execution via log4j2 JNDI lookup: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228

From version 2.16.0, this functionality has been completely removed

@eltonlaw eltonlaw changed the title Bump log4j2 version for cve-2021-44228 [vulnerability] Bump log4j2 version for cve-2021-44228 Dec 16, 2021
@dakrone
Copy link
Owner

dakrone commented Dec 22, 2021

This should probably upgrade to 2.17.0 since another release was created to address the DOS issue.

@eltonlaw
Copy link
Contributor Author

@dakrone dakrone changed the title [vulnerability] Bump log4j2 version for cve-2021-44228 Bump log4j2 version for cve-2021-44228 Jan 21, 2022
@dakrone dakrone merged commit c37f265 into dakrone:3.x Jan 21, 2022
@dakrone
Copy link
Owner

dakrone commented Jan 21, 2022

Merged, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants