Skip to content

symbol-processing-aa-embeddable is now packing CVE-2022-23305 vulnerability (log4j files) #2651

@achmyr

Description

@achmyr

Context:
With the change: 046b539, all of log4j-v1.jar files went into the jar file, including JDBCAppender class flagged by CVE-2022-23305

Recommendation from CVE: Users should upgrade to Log4j 2, as it addresses numerous other issues from the previous versions.

Consequence: This blocks KSP upgrades for all the projects protected by Security Scanner tools (like NexusIQ)

cc: @ting-yuan

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions