Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log4j 2.16.0 dependency has vulnerability CVE-2021-45105 #57

Closed
joaocfernandes opened this issue Dec 20, 2021 · 3 comments
Closed

log4j 2.16.0 dependency has vulnerability CVE-2021-45105 #57

joaocfernandes opened this issue Dec 20, 2021 · 3 comments
Assignees
Labels
bug Something isn't working

Comments

@joaocfernandes joaocfernandes added the bug Something isn't working label Dec 20, 2021
@Russell616 Russell616 self-assigned this Dec 20, 2021
@Russell616
Copy link

Hi João,

Yes, we are aware of this new vulnerability. We plan to deploy a new version of the plugin still this week.

I think the whole Java community would appreciate it if no more vulnerabilities in log4j were found...let's hope so...

@Russell616 Russell616 added the WIP This issue is currently being developed label Dec 20, 2021
Russell616 added a commit that referenced this issue Dec 20, 2021
#57 XRAYJENKINS-132 Bump version of log4j version to 2.17.0
@Russell616
Copy link

I just released the xray-connector 2.5.3, using log4j 2.17.0. Please note that it will take a few minutes until you can see the new version in your Jenkins instance.

@Russell616 Russell616 removed the WIP This issue is currently being developed label Dec 20, 2021
@joaocfernandes
Copy link
Author

Thanks a lot, once again @Russell616 !

@steigr steigr mentioned this issue Jan 6, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants