paypal / butterfly

Application transformation tool
https://paypal.github.io/butterfly/
MIT License
48 stars 50 forks source link

Update Log4j to 2.17.0 to address CVE-2021-45105 #384

Closed neel24 closed 2 years ago

neel24 commented 2 years ago

Updating Log4j version to 2.17.0 because of CVE-2021-45105 vulnerability. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45105

fabiocarvalho777 commented 2 years ago

@neel24 thanks for your contribution. I will release Butterfly version 3.2.1 now with this change. By the way, what do you use Butterfly for?

neel24 commented 2 years ago

@neel24 thanks for your contribution. I will release Butterfly version 3.2.1 now with this change. By the way, what do you use Butterfly for?

Happy to help :) I actually don't use Butterfly myself, but me and some members from cyberstormdotmu have been working on updating Log4j in several projects since the vulnerability was discovered.

fabiocarvalho777 commented 2 years ago

Got it, thanks!