commons-logging:1.2 log4j 1.2.17 vulnerability
- Dominant language
- Java
- Stars
- 276
- Forks
- 223
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug:
commons-logging 1.2 dependency is using an old log4j 1.2.17 dependency, that has many vulnerabilities as listed below:
[CVE-2019-17571](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17571) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P0
[CVE-2021-4104](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P1
[CVE-2022-23302](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P1
[CVE-2022-23305](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305) [89](https://cwe.mitre.org/data/definitions/89.html) Critical P0
[CVE-2022-23307](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P0
Client Version
54.0.0
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.