Skip to content

Update log4j-core and log4j-api dependencies to 2.17.1 #299

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Jan 4, 2022
Merged

Update log4j-core and log4j-api dependencies to 2.17.1 #299

merged 2 commits into from
Jan 4, 2022

Conversation

andclt
Copy link
Contributor

@andclt andclt commented Dec 29, 2021

Description of changes:

  • Update log4j-core and log4j-api dependencies to 2.17.1
  • Stage update to aws-lambda-java-log4j2 version 1.5.1

CVE-2021-44832

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@danotorrey
Copy link

Thanks for opening up this PR. Is there any chance to merge and release this soon-ish? Although CVE-2021-44832 is only moderate severity, we have received some requests from users to update our Lambda function to the latest version, and it probably is best to include this when we do that. Thanks in advance for the consideration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants