Update dependency org.apache.logging.log4j:log4j-core to v2.12.2 #2
Dev - Mend for GitHub.com / WhiteSource Security Check
failed
Nov 21, 2024 in 1m 28s
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2021-44228Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> ❌ log4j-core-2.12.2.jar (Vulnerable Library) |
Critical | 9.6 | log4j-core-2.12.2.jar | Upgrade to version: org.apache.logging.log4j:log4j-core:2.3.1,2.12.2,2.15.0;org.ops4j.pax.logging:pax-logging-log4j2:1.11.10,2.0.11 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2020-9488 | log4j-core-2.8.2.jar |
CVE-2021-44228 | log4j-core-2.8.2.jar |
CVE-2021-45046 | log4j-core-2.8.2.jar |
Base branch total remaining vulnerabilities: 3
Base branch commit: 3c43b311929fb206edc9220eed114c3ec234272e
Total libraries scanned: 2
Scan token: 3c04b3dbac6d4be4a65aa236af24eb52
Loading