Uploaded image for project: 'Maven'
  1. Maven
  2. MNG-7366

Maven downloading log4j version not specified in POM when building the Project.

    XMLWordPrintableJSON

Details

    • Patch, Important

    Description

      Maven downloading log4j version not specified in POM when building the Project.

      In POM i have updated my log4j to log4j core 2.16.0 to fix the Log4j Vulnerability with Older version. But even after changing the Version Maven is downloading 1.2.12 and 1.2.17 version of Log4j when running the build.

      I'm not seeing these version even in the dependency tree of my Project. 

      Please help to fix this issue as its a Critical Security Issue.

      Attachments

        1. image-2022-01-10-11-18-51-317.png
          192 kB
          Tharanadha K
        2. maven log4j issue.png
          53 kB
          Srinivasan L

        Issue Links

          Activity

            People

              Unassigned Unassigned
              srini1801 Srinivasan L
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: