[
https://issues.apache.org/jira/browse/AXIOM-510?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17460337#comment-17460337
]
Robert Lazarski commented on AXIOM-510:
---------------------------------------
Thanks for the insight. That is true. I updated the pom.xml again for 2.16.0
and the unit tests passed. Closing the issue.
Axis2 does include log4j2 2.14.1 in the WAR distro so I will be moving the
conversation there.
> Log4j2 update for CVE-2021-44228
> --------------------------------
>
> Key: AXIOM-510
> URL: https://issues.apache.org/jira/browse/AXIOM-510
> Project: Axiom
> Issue Type: Improvement
> Reporter: Robert Lazarski
> Priority: Major
> Fix For: 1.3.1
>
>
> I committed the upgrade of log4j2 to 2.15.0.
> [~veithen] , I see that you have done quite a few commits in Axiom since the
> 1.3.0 release - splendid work BTW.
> What's your thoughts on releasing Axiom for CVE-2021-44228? Axis2 and Rampart
> releases would follow.
> I did the last 1.3.0 release and volunteer for the next one - just thought
> I'd mention that.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]