You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We discussed the idea of doing an earlier release but ultimately decided to stick with our existing schedule. The main reason is we manage an awful lot of dependencies and we don’t really want to trigger releases anytime one of them has a CVE. Another factor is the fact that our out-of-the-box setup doesn’t include log4j-core.
totally agree with that in general - but this isn't exactly your average CVE. it certainly helps that it's not the default logging framework, but... still to this layman, it seems patch-worthy. thanks for the details blog post tho! that'll definitely help folks
Activity
Upgrade to Log4j2 2.15.0
zhoujia1974 commentedon Dec 10, 2021
What is the target release date for this cve patch?
scottfrederick commentedon Dec 10, 2021
@zhoujia1974 The project milestones page shows the planned dates for upcoming releases, including the
2.5.8
release that this issue is scheduled for.madorb commentedon Dec 10, 2021
considering the severity of this CVE, could that be moved up? (i know folks can fix it otherwise... but will they?)
philwebb commentedon Dec 11, 2021
We discussed the idea of doing an earlier release but ultimately decided to stick with our existing schedule. The main reason is we manage an awful lot of dependencies and we don’t really want to trigger releases anytime one of them has a CVE. Another factor is the fact that our out-of-the-box setup doesn’t include
log4j-core
.We have published a blog post about the vulnerability to help people understand their options. It’s at https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot
madorb commentedon Dec 11, 2021
totally agree with that in general - but this isn't exactly your average CVE. it certainly helps that it's not the default logging framework, but... still to this layman, it seems patch-worthy. thanks for the details blog post tho! that'll definitely help folks
mauromol commentedon Dec 13, 2021
Will this be backported to Spring Boot 2.4.x? The blog article speaks about just 2.5.x and 2.6.x.
bclozel commentedon Dec 13, 2021
@mauromol Spring Boot 2.4.x is out of OSS support.
[-]Upgrade to Log4j2 2.15.0[/-][+]Upgrade to Log4j2 2.16.0[/+]snicoll commentedon Dec 18, 2021
Reopening to upgrade to
2.17.0
perCVE-2021-45105
.[-]Upgrade to Log4j2 2.16.0[/-][+]Upgrade to Log4j2 2.17.0[/+]Upgrade to Log4j2 2.17.0
Upgrade Build to Log4j 2.17.0