Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
2.5.0
-
None
Description
There is a CVE against v2.17.0
https://github.com/apache/jclouds/blob/master/project/pom.xml#L239
https://logging.apache.org/log4j/2.x/security.html
Also, logback version is old (next line in pom)
https://mvnrepository.com/artifact/ch.qos.logback/logback-core