forcedotcom / forcedotcom/wsc

commons-logging:1.2 log4j 1.2.17 vulnerability

Open
#293 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
276
Forks
223
PR merge metrics
No merged PRs in 30d

Description

Describe the bug:
commons-logging 1.2 dependency is using an old log4j 1.2.17 dependency, that has many vulnerabilities as listed below:

[CVE-2019-17571](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17571) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P0
[CVE-2021-4104](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P1
[CVE-2022-23302](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P1
[CVE-2022-23305](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305) [89](https://cwe.mitre.org/data/definitions/89.html) Critical P0
[CVE-2022-23307](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307) [502](https://cwe.mitre.org/data/definitions/502.html) Critical P0

Client Version
54.0.0

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.