You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@druid.apache.org by GitBox <gi...@apache.org> on 2021/12/19 12:31:59 UTC

[GitHub] [druid] GElkayam edited a comment on pull request #12081: Update to log4j2 to 2.17.0

GElkayam edited a comment on pull request #12081:
URL: https://github.com/apache/druid/pull/12081#issuecomment-997384365


   Looking forward to see this in a version we can upgrade to, to clear CVE-2021-45105.
   @FrankChen021 , please note that CVE-2021-45046 didn't start with a score of 9, and yet, this is causing headache to any sysadmin running druid. So it would make sense to release a version ASAP, IMHO.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org