Sven Kubiak created LOG4J2-2329:
-----------------------------------

             Summary: Fix dependency in log4j-slf4j-impl to slf4j due to 
CVE-2018-8088
                 Key: LOG4J2-2329
                 URL: https://issues.apache.org/jira/browse/LOG4J2-2329
             Project: Log4j 2
          Issue Type: Bug
          Components: SLF4J Bridge
    Affects Versions: 2.11.0
            Reporter: Sven Kubiak


Latest version of log4j-slf4j-impl has a dependency to slf4j-api version 
1.8.0-Alpha2. All version before 1.8.0-Beta2 have vulnerable due to 
CVE-2018-8088.

[https://nvd.nist.gov/vuln/detail/CVE-2018-8088]

Can we update to at least 1.8.0-Beta2?



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to