Brahma Reddy Battula created HIVE-25797:
-------------------------------------------

             Summary: log4j2 has a critical RCE vulnerability CVE-2021-44228
                 Key: HIVE-25797
                 URL: https://issues.apache.org/jira/browse/HIVE-25797
             Project: Hive
          Issue Type: Bug
          Components: Logging, Security
    Affects Versions: 3.1.2
            Reporter: Brahma Reddy Battula


Impacted log4j version: Apache Log4j 2.x <= 2.14.1
I found that our current log4j version at master is 2.14.1.
Should upgrade the version to 2.15.0



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to