brianfrankcooper / YCSB

Yahoo! Cloud Serving Benchmark
Apache License 2.0
4.94k stars 2.24k forks source link

fix(sec): upgrade org.apache.logging.log4j:log4j-core to 2.17.1 #1650

Open zhoumengyks opened 1 year ago

zhoumengyks commented 1 year ago

What happened?

There are 1 security vulnerabilities found in org.apache.logging.log4j:log4j-core 2.7

What did I do?

Upgrade org.apache.logging.log4j:log4j-core from 2.7 to 2.17.1 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS