Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log4j vulnerability in some sample projects #32

Open
LentilHead opened this issue Jan 9, 2022 · 0 comments
Open

Log4j vulnerability in some sample projects #32

LentilHead opened this issue Jan 9, 2022 · 0 comments

Comments

@LentilHead
Copy link

It seems to me like some of the provided sample projects depend on a vulnerable log4j version.
The oauth2-server which is used in several chapters loads log4j version 2.12.1 for example.
I think you might want to consider mitigating 1 this vulnerability, even though these projects are only intended for teaching purposes.

Footnotes

  1. Log4J2 Vulnerability and Spring Boot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant