trustpilot / kafka-connect-dynamodb

A Kafka Connect Source Connector for DynamoDB
MIT License
56 stars 32 forks source link

Upgrade lo4j #14

Closed TPRobots closed 2 years ago

TPRobots commented 2 years ago

Pull request opened by github-pullrequestcreator.

anl-trustpilot commented 2 years ago

address CVE-2021-44228

HunterSherms commented 2 years ago

Looks like this will need to be repeated for 2.16.0 https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/?s=09#update-the-localhost-bypass-was-discovered

emilio-larrambebere-TP commented 2 years ago

Hi @HunterSherms thanks for the heads-up, we addressed the new vulnerabilities in https://github.com/trustpilot/kafka-connect-dynamodb/pull/15 which updates log4j to version 2.17