Skip to content
This repository has been archived by the owner on Dec 13, 2023. It is now read-only.

Force log4j dep version to 2.16 to avoid a second exploit #2643

Merged
merged 1 commit into from
Dec 15, 2021
Merged

Force log4j dep version to 2.16 to avoid a second exploit #2643

merged 1 commit into from
Dec 15, 2021

Conversation

ermineaweb
Copy link
Contributor

@ermineaweb ermineaweb commented Dec 15, 2021

Pull Request type

  • Bugfix
  • Feature
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • Other (please describe):

Changes in this PR

Update the version of log4j from 2.15 to 2.16 because the 2.15 contains a new vulnerability
sources: here or on apache log4j project

Alternatives considered

@jxu-nflx jxu-nflx merged commit 39343d3 into Netflix:main Dec 15, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants