Skip to content

#3936 Fix CVE-2021-44832 false positive for log4-api & log4j-web#3937

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
nhumblot:3936-log4j-ap-fp
Jan 3, 2022
Merged

#3936 Fix CVE-2021-44832 false positive for log4-api & log4j-web#3937
jeremylong merged 1 commit intodependency-check:mainfrom
nhumblot:3936-log4j-ap-fp

Conversation

@nhumblot
Copy link
Copy Markdown
Collaborator

@nhumblot nhumblot commented Jan 3, 2022

Fixes Issue

Description of Change

Fix #3936 by declaring CVE-2021-44832 a false positive for log4j-api & log4j-web artifacts.

Have test cases been added to cover the new functionality?

no

@boring-cyborg boring-cyborg Bot added the core changes to core label Jan 3, 2022
@jeremylong jeremylong added this to the 6.5.2 milestone Jan 3, 2022
@jeremylong jeremylong merged commit dc1be36 into dependency-check:main Jan 3, 2022
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Dec 29, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

core changes to core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

False Positive on log4j-api / log4j-web - CVE-2021-44832

2 participants