[
https://issues.apache.org/jira/browse/AVRO-3304?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17478604#comment-17478604
]
ASF subversion and git services commented on AVRO-3304:
-------------------------------------------------------
Commit 742a7679ec2845ac746469fe5a96f4e8963de56a in avro's branch
refs/heads/branch-1.11 from Ryan Skraba
[ https://gitbox.apache.org/repos/asf?p=avro.git;h=742a767 ]
AVRO-3304: Drop-in reload4j to mitigate log4j 1.x (#1464)
(cherry picked from commit bd4e91ac09d2dc6cc25e2369697dde57fb3ad2a8)
> avro-tools Update log4j dependency for critical vulnerability
> -------------------------------------------------------------
>
> Key: AVRO-3304
> URL: https://issues.apache.org/jira/browse/AVRO-3304
> Project: Apache Avro
> Issue Type: Task
> Components: tools
> Affects Versions: 1.11.0
> Reporter: Daniel Nash
> Assignee: Ryan Skraba
> Priority: Major
> Labels: pull-request-available
> Time Spent: 1h 40m
> Remaining Estimate: 0h
>
> Our company security is having a fit because Nessus scans are triggering on
> the bundled log4j in the avro-tools.jar. Please update the log4j
> dependencies to the latest versions to remove the critical vulnerability
> present in the currently bundled log4j.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)