-
Notifications
You must be signed in to change notification settings - Fork 149
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade log4j-core version to fix CVE-2021-45105 #617
Conversation
Any ETA when this going to be released? |
We are in process of updating our APM agent for nearly ~1000 apps , it would be nice if we can have any update on releasing new version so that we don't need to redeploy again to pick up new version . Thanks for approving @meiao |
@skjelmo looks like it failing checks |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Any plans for upgrading 6.5.2 to Log4j 2.12.3 ? |
We will release a 6.5.3 with log4j 2.12.3 when it is available. |
Overview
This PR upgrades
log4j-core
to the latest version (2.17.0
) to protect from uncontrolled recursion from self-referential lookups, fixing CVE-2021-45105 relevant for Java 8 and later.References:
https://logging.apache.org/log4j/2.x/security.html
https://issues.apache.org/jira/browse/LOG4J2-3230
Related Github Issue
#605
Related PR
#603
#610