Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

commons-logging:1.2 log4j 1.2.17 vulnerability #293

Open
amahfouz1 opened this issue Mar 28, 2022 · 0 comments
Open

commons-logging:1.2 log4j 1.2.17 vulnerability #293

amahfouz1 opened this issue Mar 28, 2022 · 0 comments

Comments

@amahfouz1
Copy link

amahfouz1 commented Mar 28, 2022

Describe the bug:
commons-logging 1.2 dependency is using an old log4j 1.2.17 dependency, that has many vulnerabilities as listed below:

CVE-2019-17571 502 Critical P0
CVE-2021-4104 502 Critical P1
CVE-2022-23302 502 Critical P1
CVE-2022-23305 89 Critical P0
CVE-2022-23307 502 Critical P0

Client Version
54.0.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant