Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix log4j vulnerability #485

Merged
merged 4 commits into from
Dec 14, 2021
Merged

Fix log4j vulnerability #485

merged 4 commits into from
Dec 14, 2021

Conversation

sarbajitdutta
Copy link
Contributor

https://nvd.nist.gov/vuln/detail/CVE-2021-44228

  • Update Spring boot
  • Log4j update to 2.15.0

@sarbajitdutta sarbajitdutta added the dependencies Pull requests that update a dependency file label Dec 14, 2021
@sarbajitdutta sarbajitdutta self-assigned this Dec 14, 2021
@sarbajitdutta sarbajitdutta merged commit 79342b4 into master Dec 14, 2021
@cgaylord-vt
Copy link

Will you be updating to 2.16 now that 2.15 has been identified as still problematic?

@sarbajitdutta
Copy link
Contributor Author

@cgaylord-vt Yes we are in the process of updating it. We are running some tests in dev environment. Expect the update before EOD.

@sarbajitdutta
Copy link
Contributor Author

@cgaylord-vt log4j vulnerability was patched and new version was released #487

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants