[ 
https://issues.apache.org/jira/browse/LUCENE-10303?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17457497#comment-17457497
 ] 

ASF subversion and git services commented on LUCENE-10303:
----------------------------------------------------------

Commit e111182e12ed91498962abf4700319738cd53189 in lucene's branch 
refs/heads/main from Tomoko Uchida
[ https://gitbox.apache.org/repos/asf?p=lucene.git;h=e111182 ]

LUCENE-10303: Upgrade log4j to 2.15.0


> Upgrade log4j to 2.15.0
> -----------------------
>
>                 Key: LUCENE-10303
>                 URL: https://issues.apache.org/jira/browse/LUCENE-10303
>             Project: Lucene - Core
>          Issue Type: Task
>            Reporter: Tomoko Uchida
>            Assignee: Tomoko Uchida
>            Priority: Minor
>         Attachments: LUCENE-10303.patch
>
>
> CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker 
> controlled LDAP and other JNDI related endpoints.
> Versions Affected: all versions from 2.0-beta9 to 2.14.1
> [https://logging.apache.org/log4j/2.x/security.html]
>  
> Only luke module uses log4j 2.13.2 (I grepped the entire codebase); meanwhile 
> the versions.props is shared by all subprojects, it may be better to upgrade 
> to 2.15.0 I think.



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to