You are viewing a plain text version of this content. The canonical link for it is here.
Posted to pluto-scm@portals.apache.org by as...@apache.org on 2021/12/13 19:19:15 UTC

[portals-pluto] branch master updated: PLUTO-787 Migrate to Log4j 2.15.0 due to CVE-2019-17571 and CVE-2021-44228

This is an automated email from the ASF dual-hosted git repository.

asfgriff pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/portals-pluto.git


The following commit(s) were added to refs/heads/master by this push:
     new 87fe702  PLUTO-787 Migrate to Log4j 2.15.0 due to CVE-2019-17571 and CVE-2021-44228
87fe702 is described below

commit 87fe702b2774fcd982e8842bd1d962b06d044d9f
Author: Neil Griffin <ne...@gmail.com>
AuthorDate: Mon Dec 13 14:18:39 2021 -0500

    PLUTO-787 Migrate to Log4j 2.15.0 due to CVE-2019-17571 and CVE-2021-44228
---
 .../src/main/resources/archetype-resources/build.gradle               | 2 +-
 .../src/main/resources/archetype-resources/pom.xml                    | 2 +-
 .../src/main/resources/archetype-resources/build.gradle               | 2 +-
 .../src/main/resources/archetype-resources/pom.xml                    | 2 +-
 .../src/main/resources/archetype-resources/build.gradle               | 2 +-
 .../src/main/resources/archetype-resources/pom.xml                    | 2 +-
 .../src/main/resources/archetype-resources/build.gradle               | 2 +-
 .../src/main/resources/archetype-resources/pom.xml                    | 2 +-
 pom.xml                                                               | 4 ++--
 9 files changed, 10 insertions(+), 10 deletions(-)

diff --git a/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/build.gradle b/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/build.gradle
index 8e8e1f4..df72b65 100644
--- a/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/build.gradle
+++ b/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/build.gradle
@@ -6,7 +6,7 @@ repositories {
 
 dependencies {
     compile group: 'org.slf4j', name: 'slf4j-api', version:'1.7.25'
-    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.14.1'
+    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.15.0'
     providedCompile group: 'javax.portlet', name: 'portlet-api', version:'3.0.0'
 }
 
diff --git a/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/pom.xml b/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/pom.xml
index cab4356..710171d 100644
--- a/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/pom.xml
+++ b/maven-archetypes/bean-portlet-archetype/src/main/resources/archetype-resources/pom.xml
@@ -49,7 +49,7 @@
 		<dependency>
 			<groupId>org.apache.logging.log4j</groupId>
 			<artifactId>log4j-slf4j-impl</artifactId>
-			<version>2.14.1</version>
+			<version>2.15.0</version>
 			<scope>runtime</scope>
 		</dependency>
 	</dependencies>
diff --git a/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/build.gradle b/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/build.gradle
index 8e8e1f4..df72b65 100644
--- a/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/build.gradle
+++ b/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/build.gradle
@@ -6,7 +6,7 @@ repositories {
 
 dependencies {
     compile group: 'org.slf4j', name: 'slf4j-api', version:'1.7.25'
-    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.14.1'
+    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.15.0'
     providedCompile group: 'javax.portlet', name: 'portlet-api', version:'3.0.0'
 }
 
diff --git a/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/pom.xml b/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/pom.xml
index cab4356..710171d 100644
--- a/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/pom.xml
+++ b/maven-archetypes/generic-portlet-archetype/src/main/resources/archetype-resources/pom.xml
@@ -49,7 +49,7 @@
 		<dependency>
 			<groupId>org.apache.logging.log4j</groupId>
 			<artifactId>log4j-slf4j-impl</artifactId>
-			<version>2.14.1</version>
+			<version>2.15.0</version>
 			<scope>runtime</scope>
 		</dependency>
 	</dependencies>
diff --git a/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/build.gradle b/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/build.gradle
index ec5a93c..a41e32d 100644
--- a/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/build.gradle
+++ b/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/build.gradle
@@ -6,7 +6,7 @@ repositories {
 
 dependencies {
     compile group: 'org.slf4j', name: 'slf4j-api', version:'1.7.25'
-    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.14.1'
+    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.15.0'
     compile group: 'org.apache.taglibs', name: 'taglibs-standard-jstlel', version:'1.2.1'
     providedCompile group: 'javax.mvc', name: 'javax.mvc-api', version:'1.0-pfd'
     providedCompile group: 'javax.portlet', name: 'portlet-api', version:'3.0.0'
diff --git a/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/pom.xml b/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/pom.xml
index 371dfa5..437cbfd 100644
--- a/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/pom.xml
+++ b/maven-archetypes/mvcbean-jsp-portlet-archetype/src/main/resources/archetype-resources/pom.xml
@@ -103,7 +103,7 @@
 		<dependency>
 			<groupId>org.apache.logging.log4j</groupId>
 			<artifactId>log4j-slf4j-impl</artifactId>
-			<version>2.14.1</version>
+			<version>2.15.0</version>
 			<scope>runtime</scope>
 		</dependency>
 	</dependencies>
diff --git a/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/build.gradle b/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/build.gradle
index 17a6856..8001c72 100644
--- a/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/build.gradle
+++ b/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/build.gradle
@@ -7,7 +7,7 @@ repositories {
 dependencies {
     compile group: 'org.apache.portals.pluto', name: 'thymeleaf-mvc-portlet-cdi', version:'3.1.0-SNAPSHOT'
     compile group: 'org.slf4j', name: 'slf4j-api', version:'1.7.25'
-    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.14.1'
+    compile group: 'org.apache.logging.log4j', name: 'log4j-slf4j-impl', version:'2.15.0'
     providedCompile group: 'javax.mvc', name: 'javax.mvc-api', version:'1.0-pfd'
     providedCompile group: 'javax.portlet', name: 'portlet-api', version:'3.0.0'
     providedCompile group: 'javax.validation', name: 'validation-api', version:'2.0.1.Final'
diff --git a/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/pom.xml b/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/pom.xml
index f2ef61c..b407875 100644
--- a/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/pom.xml
+++ b/maven-archetypes/mvcbean-thymeleaf-portlet-archetype/src/main/resources/archetype-resources/pom.xml
@@ -95,7 +95,7 @@
 		<dependency>
 			<groupId>org.apache.logging.log4j</groupId>
 			<artifactId>log4j-slf4j-impl</artifactId>
-			<version>2.14.1</version>
+			<version>2.15.0</version>
 			<scope>runtime</scope>
 		</dependency>
 	</dependencies>
diff --git a/pom.xml b/pom.xml
index a277b52..a8b4aa5 100644
--- a/pom.xml
+++ b/pom.xml
@@ -279,12 +279,12 @@ generate mailto links. -->
 			<dependency>
 				<groupId>org.apache.logging.log4j</groupId>
 				<artifactId>log4j-core</artifactId>
-				<version>2.14.1</version>
+				<version>2.15.0</version>
 			</dependency>
 			<dependency>
 				<groupId>org.apache.logging.log4j</groupId>
 				<artifactId>log4j-slf4j-impl</artifactId>
-				<version>2.14.1</version>
+				<version>2.15.0</version>
 			</dependency>
 			<dependency>
 				<groupId>org.slf4j</groupId>