Skip to content
This repository has been archived by the owner on Jun 29, 2023. It is now read-only.

Upgrade dependencies #284

Closed
3 tasks done
swyrik opened this issue Jan 5, 2022 · 1 comment
Closed
3 tasks done

Upgrade dependencies #284

swyrik opened this issue Jan 5, 2022 · 1 comment
Labels
type: dependency-upgrade A dependency upgrade
Milestone

Comments

@swyrik
Copy link

swyrik commented Jan 5, 2022

Make sure that:

  • You have read the contribution guidelines.
  • You specify the logstash-gelf version and environment so it's obvious which version is affected
  • You provide a reproducible test case (either descriptive of as JUnit test) if it's a bug or the expected behavior differs from the actual behavior.
@swyrik
Copy link
Author

swyrik commented Jan 5, 2022

Please update the log4j 2 version to the log4j 2.17.0 and above. As the current versions are susceptible to CVE-2021-44832 Security Vulnerability.

affected versions: logstash-gelf-1.14.0.jar, logstash-gelf-1.14.1.jar

@mp911de mp911de changed the title Update Log4j Version to 2.17.0 and above Upgrade dependencies Jan 21, 2022
@mp911de mp911de added this to the 1.15.0 milestone Jan 21, 2022
@mp911de mp911de added the type: dependency-upgrade A dependency upgrade label Jan 21, 2022
mp911de added a commit that referenced this issue Jan 21, 2022
Logj4 1.2.17, Log4j2 2.17.1, AssertJ 3.22.0, Mockito 4.2.0, Jackson 2.13.1, Commons Pool 2.11.1, Logback Classic 1.2.10, Netty 4.1.73, Kafka 2.8.0
mp911de added a commit that referenced this issue Jan 21, 2022
Use newer TLS version to avoid disabled protocol errors.
@mp911de mp911de closed this as completed Jan 21, 2022
@mp911de mp911de mentioned this issue Jan 21, 2022
3 tasks
mp911de added a commit that referenced this issue Jan 21, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
type: dependency-upgrade A dependency upgrade
Projects
None yet
Development

No branches or pull requests

2 participants