-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Description
Log4j v1.2.17 is linked to multiple >8 level CVEs (Common Vulnerabilities & Exposures). This could lead to leaked data or even arbitrary code execution.
Resolution
Update Log4j dependencies to latest version
Recommended: Use a tool like Snyk to automatically scan for vulnerable dependencies using GitHub Actions.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17571
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels