Skip to content

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Aug 7, 2025

Upgrade org.apache.logging.log4j:log4j-core from 2.9.1 to 2.12.4

This pull request upgrades org.apache.logging.log4j:log4j-core from version 2.9.1 to 2.12.4 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2021-44228 Remote code injection in Log4j. Remote code injection in Log4j

| CVE-2021-45046 | Incomplete fix for Apache Log4j vulnerability. Incomplete fix for Apache Log4j vulnerability |

| CVE-2021-45105 | Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion. Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion |

| CVE-2020-9488 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. Improper validation of certificate with host mismatch in Apache Log4j SMTP appender |

| CVE-2021-44832 | Improper Input Validation and Injection in Apache Log4j2. Improper Input Validation and Injection in Apache Log4j2 |

This upgrade enhances the security and stability of the org.apache.logging.log4j:log4j-core dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant