justb4 / docker-jmeter

Docker image for Apache JMeter
MIT License
278 stars 310 forks source link

update jmeter to 5.4.2 #51

Closed anasoid closed 2 years ago

anasoid commented 2 years ago

update jmeter to 5.4.2 for security CVE-2021-45046 & CVE-2021-45046 as formatMsgNoLookups is not suffisent

https://jmeter.apache.org/changes.html#Non-functional%20changes

Other insufficient mitigation measures are: setting system property log4j2.formatMsgNoLookups or environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true for releases >= 2.10, or modifying the logging configuration to disable message lookups with %m{nolookups}, %msg{nolookups} or %message{nolookups} for releases >= 2.7 and <= 2.14.1.

justb4 commented 2 years ago

Thanks @anasoid !