Skip to content

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Aug 4, 2025

This PR contains the following updates:

Package Type Update Change
org.apache.logging.log4j:log4j-core (source) compile minor 2.8.22.25.3

By merging this PR, the issue #160 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
Critical Critical 10.0 CVE-2021-44228
Critical Critical 9.0 CVE-2021-45046
Medium Medium 6.6 CVE-2021-44832
Medium Medium 5.9 CVE-2021-45105
Medium Medium 5.4 CVE-2025-68161
Low Low 3.7 CVE-2020-9488

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 4, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-org.apache.logging.log4j-log4j-core-2.x branch from b8f9713 to 3031812 Compare November 29, 2025 12:41
@mend-for-github-com mend-for-github-com bot changed the title Update dependency org.apache.logging.log4j:log4j-core to v2.12.4 (main) Update dependency org.apache.logging.log4j:log4j-core to v2.12.2 (main) Nov 29, 2025
@mend-for-github-com mend-for-github-com bot changed the title Update dependency org.apache.logging.log4j:log4j-core to v2.12.2 (main) Update dependency org.apache.logging.log4j:log4j-core to v2.25.3 (main) Dec 19, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-org.apache.logging.log4j-log4j-core-2.x branch from 3031812 to 67520fa Compare December 19, 2025 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants