[Snyk] Security upgrade org.apache.logging.log4j:log4j-core from 2.14.1 to 2.17.0#1
[Snyk] Security upgrade org.apache.logging.log4j:log4j-core from 2.14.1 to 2.17.0#1DK7705 wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
|
This upgrade from version 2.14.1 to 2.17.0 is critical for security, as it addresses the series of vulnerabilities related to Log4Shell (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105). However, the fixes introduce significant breaking changes. Breaking Changes:
Recommendation: This is a mandatory security upgrade. Developers must verify that application code and logging configurations do not rely on the removed message lookup functionality. Any use of JNDI features must be explicitly re-enabled using the new system properties in v2.17.0. Thoroughly test logging behavior after the upgrade. Source: Apache Log4j Release Notes
|
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
app/api-gateway/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
2.14.1->2.17.0Proof of ConceptBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS)