-
Notifications
You must be signed in to change notification settings - Fork 239
Update to log4j2 2.16.0 #289
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Now a must to update to 2.16: https://logging.apache.org/log4j/2.x/security.html |
Thanks for taking care so quickly. Do you have an ETA for the release? |
It's available now https://repo1.maven.org/maven2/com/amazonaws/aws-lambda-java-log4j2/ |
Awesome, thank you so much 🙂 |
Closing issue since |
The log4j dependencies were recently updated to
2.15.0
in #285 to mitigate CVE-2021-44228.A subsequent log4j version (
2.16.0
) was released yesterday that completely disables JNDI by default. Should the project be updated to this new version?https://logging.apache.org/log4j/2.x/changes-report.html#a2.16.0
The text was updated successfully, but these errors were encountered: