You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>This version is a fix release against the vulnerability CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints.
50
+
<p>This version is a fix release against the vulnerability CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted.
51
51
</p>
52
52
<ul>
53
53
<li><ahref="#New and Noteworthy">New and Noteworthy</a></li>
@@ -114,7 +114,7 @@ Summary
114
114
115
115
<ch_section>Non-functional changes</ch_section>
116
116
<ul>
117
-
<li>Updated Apache log4j2 to 2.16.0 (from 2.13.3).</li>
117
+
<li>Updated Apache Log4j2 to 2.17.0 (from 2.16.0).</li>
0 commit comments