spring-cloud / spring-cloud-consul

Spring Cloud Consul
http://cloud.spring.io/spring-cloud-consul/
Apache License 2.0
813 stars 541 forks source link

About the CVE-2021-44228 vulnerability of log4j2 #761

Closed yyddz closed 1 year ago

yyddz commented 2 years ago

Is spring-cloud-consul affected by the CVE-2021-44228 vulnerability of log4j2? Do we have plans to upgrade log4j2 to 2.16.0?

dota17 commented 2 years ago

Do we have plans to upgrade log4j2 to 2.117.1? CVE-2021-45105 affected.

spencergibb commented 1 year ago

All log4j dependencies are managed by spring boot and the upgrades have taken place there