[ https://issues.apache.org/jira/browse/CASSANDRA-16464?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17293193#comment-17293193 ]
Bhargav Joshi commented on CASSANDRA-16464: ------------------------------------------- Jermiah, do have directions to build with upgraded log back, is there branch ? > Upgrade to logback package 1.2.0 or later fix high vulnerabilities > ------------------------------------------------------------------ > > Key: CASSANDRA-16464 > URL: https://issues.apache.org/jira/browse/CASSANDRA-16464 > Project: Cassandra > Issue Type: Improvement > Components: Dependencies > Reporter: Bhargav Joshi > Assignee: Brandon Williams > Priority: Normal > Fix For: 3.0.x > > > Tag | Distro | CVE ID | Severity | Packages | Source Package | Fix Package > Version > -- | -- | -- | -- | -- | -- | -- > v0.1.22 | Ubuntu-bionic | CVE-2017-5929 | critical | > ch.qos.logback_logback-core | 1.1.3 | fixed in 1.2.0 -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscr...@cassandra.apache.org For additional commands, e-mail: commits-h...@cassandra.apache.org