Skip to content

Upgrade cloudformation-cli-java-plugin dependency to 2.0.10

Critical
prerna-p published GHSA-rqf9-7x3q-jh3g Jan 4, 2022

Package

maven cloudformation-cli-java-plugin (Maven)

Affected versions

< 2.0.10

Patched versions

2.0.10

Description

Description

AWS CloudFormation has updated cloudformation-cli-java-plugin to mitigate published security issues in Log4j2.

How to determine if you are impacted?

Go to your project’s pom.xml file and look for the cloudformation-cli-java-plugin dependency and check if the version is less than the recommended version 2.0.10.

Remediation

  • Upgrade projects to use version 2.0.10 or higher.
  • Publish any CloudFormation Registry extensions owned by you with a new version that includes this fix.

References

Severity

Critical

CVE ID

CVE-2021-45105

Weaknesses

No CWEs