Upgrade to Log4J 2 2.16.0

Description

The infamous CVE was supposedly fixed already by the previous release, but this version goes a step further in prevention by fully removing JNDI support and messages lookup.

https://logging.apache.org/log4j/2.x/changes-report.html#a2.16.0

Activity

Show:
Fixed

Details

Assignee

Reporter

Priority

Created December 14, 2021 at 9:44 PM
Updated December 15, 2021 at 12:57 PM
Resolved December 15, 2021 at 12:48 PM