salesforce-marketingcloud / FuelSDK-Java

Salesforce Marketing Cloud Java SDK
BSD 3-Clause "New" or "Revised" License
72 stars 123 forks source link

[CVE-2021-44228] upgrades logging to log4j 2.16.0 to mitigate RCE #134

Closed roechi closed 2 years ago

roechi commented 2 years ago

Fixes salesforce-marketingcloud/FuelSDK-Java#133

This addresses RCE vulnerabilities expressed through CVE-2021-44228 and vulnerabilities which exist for prior versions of log4j 1.x

I was not able to run all tests since I was not able to figure out all requirements for my build environment.

roechi commented 2 years ago

Fix released with v1.6.0.