Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
4.0.0
-
None
Description
Storage API also brings in log4j2 dependency <= 2.14.1 that can still expose a vulnerability in hive
Attachments
Issue Links
- duplicates
-
HIVE-25839 Upgrade Log4j2 to 2.17.1 due to CVE-2021-44832
- Closed
- is part of
-
HIVE-25795 [CVE-2021-44228] Update log4j2 version to 2.15.0
- Closed