Skip to content

Upgrade to Log4j2 2.17.0 #28983

@snicoll

Description

@snicoll
Member
No description provided.

Activity

added this to the 2.5.8 milestone on Dec 10, 2021
pinned this issue on Dec 10, 2021
added a commit that references this issue on Dec 10, 2021
1d8e3a8
zhoujia1974

zhoujia1974 commented on Dec 10, 2021

@zhoujia1974

What is the target release date for this cve patch?

scottfrederick

scottfrederick commented on Dec 10, 2021

@scottfrederick
Contributor

@zhoujia1974 The project milestones page shows the planned dates for upcoming releases, including the 2.5.8 release that this issue is scheduled for.

madorb

madorb commented on Dec 10, 2021

@madorb

considering the severity of this CVE, could that be moved up? (i know folks can fix it otherwise... but will they?)

locked and limited conversation to collaborators on Dec 10, 2021
philwebb

philwebb commented on Dec 11, 2021

@philwebb
Member

We discussed the idea of doing an earlier release but ultimately decided to stick with our existing schedule. The main reason is we manage an awful lot of dependencies and we don’t really want to trigger releases anytime one of them has a CVE. Another factor is the fact that our out-of-the-box setup doesn’t include log4j-core.

We have published a blog post about the vulnerability to help people understand their options. It’s at https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot

unlocked this conversation on Dec 11, 2021
madorb

madorb commented on Dec 11, 2021

@madorb

totally agree with that in general - but this isn't exactly your average CVE. it certainly helps that it's not the default logging framework, but... still to this layman, it seems patch-worthy. thanks for the details blog post tho! that'll definitely help folks

locked and limited conversation to collaborators on Dec 11, 2021
unlocked this conversation on Dec 12, 2021
mauromol

mauromol commented on Dec 13, 2021

@mauromol

Will this be backported to Spring Boot 2.4.x? The blog article speaks about just 2.5.x and 2.6.x.

bclozel

bclozel commented on Dec 13, 2021

@bclozel
Member
unpinned this issue on Dec 13, 2021
pinned this issue on Dec 13, 2021
unpinned this issue on Dec 14, 2021
changed the title [-]Upgrade to Log4j2 2.15.0[/-] [+]Upgrade to Log4j2 2.16.0[/+] on Dec 15, 2021
snicoll

snicoll commented on Dec 18, 2021

@snicoll
MemberAuthor

Reopening to upgrade to 2.17.0 per CVE-2021-45105.

changed the title [-]Upgrade to Log4j2 2.16.0[/-] [+]Upgrade to Log4j2 2.17.0[/+] on Dec 18, 2021
added a commit that references this issue on Dec 18, 2021
cb02944
added a commit that references this issue on Dec 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

      Development

      No branches or pull requests

        Participants

        @scottfrederick@bclozel@snicoll@philwebb@madorb

        Issue actions

          Upgrade to Log4j2 2.17.0 · Issue #28983 · spring-projects/spring-boot