Skip to content

Log4j fix round 3#2416

Merged
danielabutano merged 1 commit intointermine:devfrom
asherpasha:log4j-3
Jan 6, 2022
Merged

Log4j fix round 3#2416
danielabutano merged 1 commit intointermine:devfrom
asherpasha:log4j-3

Conversation

@asherpasha
Copy link
Contributor

@asherpasha asherpasha commented Dec 29, 2021

Details

This pull request fixes CVE-2021-44832 (also RCE bug). Log4j 2.17.0 is upgraded to 2.17.1. I am not sure if InterMine is exploitable using these Log4j bugs, but we should fix this for compliance, department security policy etc.

Testing

Works on GitHub actions

Checklist

Before your pull request can be approved, be sure to check all boxes:

  • Passing unit test for new or updated code (if applicable)
  • Passes all tests – according to Travis
  • Documentation (if applicable)
  • Single purpose
  • Detailed commit messages
  • Well commented code
  • Checkstyle

@danielabutano danielabutano merged commit 22e82dd into intermine:dev Jan 6, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants