Details
-
Bug
-
Status: Resolved
-
Blocker
-
Resolution: Unresolved
-
None
-
None
Description
It's been recently reported that JNDI features of log4j2 versions >= 2-beta9 <= 2.15 are affected by 0-day vulnerability that might execute arbitrary code iff attacker's string will get logged.
More details could be found here:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
We need to make sure that neither of this versions is present in Hudi's direct/transitive deps.