Details
-
Dependency upgrade
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
Groovy doesn't bundle a version of Log4j in its distribution nor list it as a dependency in its pom (or bom), so isn't directly affected by CVE-2021-45046 (see https://logging.apache.org/log4j/2.x/security.html).
However Groovy users using the Log4j2 AST transform (or using Log4j2 directly) may wish to update there version of Log4j or note the security workarounds mentioned in the above security vulnerability link.
See also:
LOG4J2-3221JNDI lookups in layout (not message patterns) enabled in Log4j2 < 2.16.0- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046
Attachments
Issue Links
- is related to
-
GROOVY-10408 Bump log4j2 version to 2.15.0 (test dependency)
- Closed
- relates to
-
GROOVY-10425 Bump log4j2 version to 2.17.0 (test dependency)
- Closed