-
-
Notifications
You must be signed in to change notification settings - Fork 446
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump: log4j to 2.15.0 #1839
Bump: log4j to 2.15.0 #1839
Conversation
Codecov Report
@@ Coverage Diff @@
## main #1839 +/- ##
=========================================
Coverage 75.69% 75.69%
Complexity 2194 2194
=========================================
Files 218 218
Lines 7810 7810
Branches 828 828
=========================================
Hits 5912 5912
Misses 1496 1496
Partials 402 402 Continue to review full report at Codecov.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Thanks! |
Hello, is it version had been updated on central? 5.0.5 does not have this CVE? Thanks in advance. |
https://github.com/getsentry/sentry-java/releases/tag/5.5.0 |
📜 Description
Bump log4j-api,log4j-core from 2.13.3 to 2.15.0
💡 Motivation and Context
CVE-2021-44228
Log4j versions prior to 2.15.0 are subject to a remote code execution vulnerability via the ldap JNDI parser.
💚 How did you test it?
📝 Checklist
🔮 Next steps