Skip to content

[Enhancement] Update log4j to 2.17.1 (or newer) #735

@pjfanning

Description

@pjfanning

Search before asking

  • I had searched in the issues and found no similar issues.

Enhancement Request

https://github.com/apache/incubator-eventmesh/blob/master/build.gradle#L412 -- shows that log4j 2.17.0 is used but this too has a CVE. https://logging.apache.org/log4j/2.x/security.html

Describe the solution you'd like

Update to v 2.17.1 or higher

Are you willing to submit PR?

  • Yes I am willing to submit a PR!

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions