[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.14.1 to 2.25.4 #174
[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.14.1 to 2.25.4
#174
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804
|
This upgrade spans multiple significant releases, including the critical security updates that addressed the Log4Shell vulnerability (CVE-2021-44228). It introduces several breaking changes and important behavioral modifications that require verification. Key Breaking Changes:
Recommendation: Due to the security-driven breaking changes, you must carefully review your logging configurations (
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804
This is a PR from Snyk, initiated by the Security team, to fix 3 vulnerabilities in the dependencies of this project.
Snyk changed the following file(s):
Important
#sca-supportSlack channel.References: