thx / RAP

Web接口管理工具,开源免费,接口自动化,MOCK数据自动生成,自动化测试,企业级管理。阿里妈妈MUX团队出品!阿里巴巴都在用!1000+公司的选择!RAP2已发布请移步至https://github.com/thx/rap2-delos
http://rap2.taobao.org
GNU General Public License v3.0
10.57k stars 2.51k forks source link

fix(sec): upgrade org.apache.logging.log4j:log4j-core to 2.17.1 #1326

Open pen4 opened 1 year ago

pen4 commented 1 year ago

What happened?

There are 1 security vulnerabilities found in org.apache.logging.log4j:log4j-core 2.5

What did I do?

Upgrade org.apache.logging.log4j:log4j-core from 2.5 to 2.17.1 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS Signed-off-by:pen4948453219@qq.com