awslabs / disco

A suite of tools including a framework for creating Java Agents, for aspect-oriented tooling for distributed systems.
Apache License 2.0
55 stars 12 forks source link

Upgrade log4j to the latest 2.17.2 #22

Closed hydo-amzn closed 2 years ago

hydo-amzn commented 2 years ago

Description of changes: log4j-core-2.13.3 has some vulnerabilities https://cwe.mitre.org/data/definitions/502.html and https://nvd.nist.gov/vuln/detail/CVE-2021-44228 so we want to use the latest version of 2.17.2

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.