Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(Plugins): Upgrade log4j to version 2.16.0 #10363

Conversation

atlasgurus
Copy link
Contributor

Additional fixes had to be introduced to log4j to address the zero day attack vulnerability. Hopefully this will be the end of it.

Closes: #10337

@codecov
Copy link

codecov bot commented Dec 15, 2021

Codecov Report

Merging #10363 (c033f4f) into master (c1df4f8) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master   #10363   +/-   ##
=======================================
  Coverage   85.37%   85.37%           
=======================================
  Files         340      340           
  Lines       14000    14000           
=======================================
  Hits        11953    11953           
  Misses       2047     2047           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update c1df4f8...c033f4f. Read the comment docs.

Copy link
Contributor

@medikoo medikoo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @atlasgurus !

@medikoo medikoo merged commit 7de020b into serverless:master Dec 15, 2021
@atlasgurus atlasgurus deleted the issue-10337-log4j-security-CVE-2021-44228 branch December 20, 2021 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Critical security issue in log4j version 2.14 and below: CVE-2021-44228
2 participants