[
https://issues.apache.org/jira/browse/GROOVY-10410?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Paul King closed GROOVY-10410.
------------------------------
> Bump log4j2 version to 2.16.0 (test dependency)
> -----------------------------------------------
>
> Key: GROOVY-10410
> URL: https://issues.apache.org/jira/browse/GROOVY-10410
> Project: Groovy
> Issue Type: Dependency upgrade
> Reporter: Paul King
> Assignee: Paul King
> Priority: Major
> Fix For: 3.0.10, 4.0.0-rc-2
>
>
> Groovy doesn't bundle a version of Log4j in its distribution nor list it as a
> dependency in its pom (or bom), so isn't directly affected by CVE-2021-45046
> (see https://logging.apache.org/log4j/2.x/security.html).
> However Groovy users using the {{Log4j2}} AST transform (or using Log4j2
> directly) may wish to update there version of Log4j or note the security
> workarounds mentioned in the above security vulnerability link.
> See also:
> * LOG4J2-3221 JNDI lookups in layout (not message patterns) enabled in Log4j2
> < 2.16.0
> * https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046
--
This message was sent by Atlassian Jira
(v8.20.1#820001)