From 5678db5c563cbdb91fa6dc8b67425f6ec073935f Mon Sep 17 00:00:00 2001 From: RJ Sheperd Date: Mon, 13 Dec 2021 09:40:43 -0800 Subject: [PATCH] Update log4j to 2.15.0 [CVE-2021-44228] Update log4j to patch for vulnerability found where arbitrary code execution can occur. See: https://nvd.nist.gov/vuln/detail/CVE-2021-44228 --- deps.edn | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/deps.edn b/deps.edn index 3e8d819..c81e993 100644 --- a/deps.edn +++ b/deps.edn @@ -42,7 +42,7 @@ com.microsoft.sqlserver/mssql-jdbc {:mvn/version "8.2.1.jre8"} ;; supplementary test stuff ;; use log4j 2.x: - org.apache.logging.log4j/log4j-api {:mvn/version "2.14.1"} + org.apache.logging.log4j/log4j-api {:mvn/version "2.15.0"} ;; bridge into log4j: org.apache.logging.log4j/log4j-1.2-api {:mvn/version "2.14.1"} org.apache.logging.log4j/log4j-jcl {:mvn/version "2.14.1"}