Re: Mapping CVEs to Log4j and Java versions.

2021-12-24 Thread Gary Gregory
On Fri, Dec 24, 2021 at 5:35 PM Ralph Goers wrote: > The stuff on the about page is “news” and will disappear in an upcoming > release. The security page will stick around indefinitely. > Ah, I did not get that. Now I do. Gary > > Ralph > > > On Dec 24, 2021, at 3:20 PM, Gary Gregory > wrote

Re: Mapping CVEs to Log4j and Java versions.

2021-12-24 Thread Ralph Goers
The stuff on the about page is “news” and will disappear in an upcoming release. The security page will stick around indefinitely. Ralph > On Dec 24, 2021, at 3:20 PM, Gary Gregory wrote: > > Hi All: > > I find it hard to track what CVE is associated with what Log4j version and > Java version

Mapping CVEs to Log4j and Java versions.

2021-12-24 Thread Gary Gregory
Hi All: I find it hard to track what CVE is associated with what Log4j version and Java version, so I created this table: https://github.com/apache/logging-log4j2/blob/release-2.x/docs/cve-map.md In general, I'm not a fan of duplicating information like we do on our About page and Security page,