ranger-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Velmurugan Periasamy (Jira)" <j...@apache.org>
Subject [jira] [Commented] (RANGER-2782) Upgrade log4j dependency
Date Thu, 09 Apr 2020 21:02:00 GMT

    [ https://issues.apache.org/jira/browse/RANGER-2782?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17079999#comment-17079999
] 

Velmurugan Periasamy commented on RANGER-2782:
----------------------------------------------

I see the review request is discarded. Will you be providing an updated patch?  

> Upgrade log4j dependency
> ------------------------
>
>                 Key: RANGER-2782
>                 URL: https://issues.apache.org/jira/browse/RANGER-2782
>             Project: Ranger
>          Issue Type: Bug
>          Components: Ranger
>    Affects Versions: 2.0.0
>            Reporter: Bolke de Bruin
>            Assignee: Bolke de Bruin
>            Priority: Blocker
>             Fix For: 2.1.0
>
>         Attachments: 0001-RANGER-2782-Upgrade-log4j-to-a-supported-version.patch
>
>
> The current log4j version in ranger is end of life and contains critical security Vulnerabilities
> CVE-2019-17571



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Mime
View raw message