Uploaded image for project: 'Maven Doxia'
  1. Maven Doxia
  2. DOXIA-610

Update doxia-module-fo to not use log4j

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.9.1
    • 1.10
    • Module - FO
    • None

    Description

      This is critical for a release.  The version of log4j is 1.2.17 and contains the following security risk:

      CVE_2020_9488

      This should be updated to use org.apache.logging.log4j:log4j-core:2.13.2

      Attachments

        Issue Links

          Activity

            People

              slachiewicz Sylwester Lachiewicz
              buddybu John Burnham
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: