GitHub user noren95 created a discussion: CVE-2021-45046/GHSA-7rjr-3q55-vv33 backport to 2.3.x is not reported on GHSA advisory
Hi log4j team - I was invetigating this CVE's affected scope, and I've noticed that the fix was backported to 2.3.x branch. Log4j advisory reports its fixed in 2.3.1. https://logging.apache.org/security.html#CVE-2021-45046 Also reflected in changelog https://github.com/apache/logging-log4j2/compare/rel/2.3...rel/2.3.1 This is not reflected in the GHSA affected range, and raises False Positive on dependency scanning. I have opened this PR on GHSA but haven't got a response yet - could someone please confirm this? https://github.com/github/advisory-database/pull/8692 I appreciate you help, thank you! GitHub link: https://github.com/apache/logging-log4j2/discussions/4236 ---- This is an automatically sent email for [email protected]. To unsubscribe, please send an email to: [email protected]
