Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MeterianBot has fixed one issue in your codebase #2

Open
wants to merge 2 commits into
base: 2.15
Choose a base branch
from

Conversation

github-actions[bot]
Copy link

@github-actions github-actions bot commented Dec 15, 2021

Hey! We’ve found issues with some of the libraries you are using in your project, MeterianBot managed to fix some of them for you but unfortunately not all of them. They just need your approval.

The security score of your project is 100, the stability score 100 and the licensing score 100.
You can have a more detailed look at the report here.

Fixes

  • We’ve updated org.apache.logging.log4j:log4j-core 2.15.0 to 2.16.0 minor release, because of CVE-2021-45046.

    Threat severity: MEDIUM      CVSS score: 4

The fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack.


Issues

  • org.apache.logging.log4j:log4j-api 2.14.1 is outdated.

    org.apache.logging.log4j:log4j-api 2.16.0 minor release is the latest available version.


Licenses

Have a look at the report for more details and find out how a licenses can impact your business.
Test

@github-actions github-actions bot added the meterian-bot-pr Pull requests that update dependency files based on Meterian's analysis label Dec 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
meterian-bot-pr Pull requests that update dependency files based on Meterian's analysis
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant