Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] #3066

Closed
tapandave035 opened this issue Dec 13, 2021 · 1 comment
Closed

[BUG] #3066

tapandave035 opened this issue Dec 13, 2021 · 1 comment

Comments

@tapandave035
Copy link

Describe the bug
Log4j version update to 2.15.0 and above due to recent vulnerability.
On December 9, 2021, a very serious vulnerability in the popular Java-based logging package Log4j was widely disclosed. This vulnerability allows an attacker to execute code on a remote server.

To Reproduce
Please follow below steps:
https://blog.cloudflare.com/how-cloudflare-security-responded-to-log4j2-vulnerability/

Expected behavior
This vulnerability allows an attacker to execute code on a remote server:

https://www.randori.com/blog/cve-2021-44228/

Version info (please complete the following information):

  • Lombok version 1.18.20
  • Platform (java 8)

Additional context
Please help us with updated version of Lombok having Log4j version 2.15.0 and above with formatMsgNoLookups=true
Or Kindly help us with the command to update the Log4j version inside Lombok dependencies.

@abimarank @stephenh @wesley Workman

@rspilker
Copy link
Collaborator

Duplicate of #3063

@rspilker rspilker marked this as a duplicate of #3063 Dec 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants