Skip to content

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Jan 9, 2024

This PR contains the following updates:

Package Type Update Change
org.apache.logging.log4j:log4j-core (source) compile minor 2.8.2 -> 2.12.4

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Critical Critical 10.0 CVE-2021-44228
Critical Critical 9.0 CVE-2021-45046
Medium Medium 6.6 CVE-2021-44832
Medium Medium 5.9 CVE-2021-45105
Low Low 3.7 CVE-2020-9488

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jan 9, 2024
@mend-for-github-com mend-for-github-com bot changed the title Update dependency org.apache.logging.log4j:log4j-core to v2.12.4 Update dependency org.apache.logging.log4j:log4j-core to v2.12.4 - autoclosed Jun 8, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/org.apache.logging.log4j-log4j-core-2.x branch June 8, 2025 06:48
@mend-for-github-com mend-for-github-com bot changed the title Update dependency org.apache.logging.log4j:log4j-core to v2.12.4 - autoclosed Update dependency org.apache.logging.log4j:log4j-core to v2.12.4 Jun 9, 2025
@mend-for-github-com mend-for-github-com bot reopened this Jun 9, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/org.apache.logging.log4j-log4j-core-2.x branch from 0795a13 to bc96511 Compare June 9, 2025 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants