[ 
https://issues.apache.org/jira/browse/FLINK-37810?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17952405#comment-17952405
 ] 

Ferenc Csaky edited comment on FLINK-37810 at 5/19/25 3:47 PM:
---------------------------------------------------------------

[{{17a32f8}}|https://github.com/apache/flink/commit/17a32f85d66b82f4bd71fce78ebf94a6e778b6c8]
 in master
[{{add6f81}}|https://github.com/apache/flink/commit/add6f810b7aa4c60550ab288bb9593fe92ee7189]
 in release-2.0
[{{df1f5c0}}|https://github.com/apache/flink/commit/df1f5c04ca2a0ddfd8b1412be6becf296553bd83]
 in release-1.20


was (Author: JIRAUSER306586):
[{{17a32f8}}|https://github.com/apache/flink/commit/17a32f85d66b82f4bd71fce78ebf94a6e778b6c8]
 in master
[{{add6f81}}|https://github.com/apache/flink/commit/add6f810b7aa4c60550ab288bb9593fe92ee7189]
 in release-2.0

> update  log4j to 2.24.3 to fix critical vulnerabilities
> -------------------------------------------------------
>
>                 Key: FLINK-37810
>                 URL: https://issues.apache.org/jira/browse/FLINK-37810
>             Project: Flink
>          Issue Type: Technical Debt
>    Affects Versions: 2.0.0, 1.20.1
>            Reporter: david radley
>            Assignee: david radley
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 1.20.2, 2.0.1
>
>
> flink Master and v2 are at 2.24.1 but there are 2 critical issues at that 
> level.
> See [2.24.3 release notes |#release-notes-2-24-3]] for details. Update  log4j 
> to 2.24.3 to resolve those issues. 
>  
> PR available 
> [https://github.com/apache/flink/pull/26570|https://github.com/apache/flink/pull/26570)]



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to