Details
-
Task
-
Status: Resolved
-
Critical
-
Resolution: Duplicate
-
8.11.1
-
None
-
None
Description
We should update to Log4j 2.17.1 to address CVE-2021-44832: Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration.
Attachments
Issue Links
- duplicates
-
SOLR-15871 Update Log4J2 version to 2.17.1
- Closed
-
SOLR-15889 Upgrade to Log4j 2.17.1
- Resolved