streamnative / bookkeeper-achieved

Apache Bookkeeper
https://bookkeeper.apache.org
Apache License 2.0
3 stars 2 forks source link

ISSUE-2815: Upgrade to log4j2 to get rid of CVE-2019-17571 #411

Closed sijie closed 3 years ago

sijie commented 3 years ago

Original Issue: apache/bookkeeper#2815


BUG REPORT

Describe the bug

Log4j1.x has a relevant and public security vulnerability: CVE-2019-17571. The solution is to upgrade Bookkeeper to log4j2 to remove that CVE.

To Reproduce

Scanning Bookkeeper image reports this CVE.

Expected behavior

Remove CVE from Bookkeeper.

Screenshots

n/a

Additional context

n/a