GitHub user noren95 created a discussion: CVE-2021-45046/GHSA-7rjr-3q55-vv33 
backport to 2.3.x is not reported on GHSA advisory

Hi log4j team -
I was invetigating this CVE's affected scope, and I've noticed that the fix was 
backported to 2.3.x branch. 

Log4j advisory reports its fixed in 2.3.1. 
https://logging.apache.org/security.html#CVE-2021-45046
Also reflected in changelog 
https://github.com/apache/logging-log4j2/compare/rel/2.3...rel/2.3.1

This is not reflected in the GHSA affected range, and raises False Positive on 
dependency scanning.
I have opened this PR on GHSA but haven't got a response yet - could someone 
please confirm this?
https://github.com/github/advisory-database/pull/8692

I appreciate you help, thank you!

GitHub link: https://github.com/apache/logging-log4j2/discussions/4236

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to