[ https://issues.apache.org/jira/browse/FLINK-37810?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17952405#comment-17952405 ]
Ferenc Csaky edited comment on FLINK-37810 at 5/19/25 3:47 PM: --------------------------------------------------------------- [{{17a32f8}}|https://github.com/apache/flink/commit/17a32f85d66b82f4bd71fce78ebf94a6e778b6c8] in master [{{add6f81}}|https://github.com/apache/flink/commit/add6f810b7aa4c60550ab288bb9593fe92ee7189] in release-2.0 [{{df1f5c0}}|https://github.com/apache/flink/commit/df1f5c04ca2a0ddfd8b1412be6becf296553bd83] in release-1.20 was (Author: JIRAUSER306586): [{{17a32f8}}|https://github.com/apache/flink/commit/17a32f85d66b82f4bd71fce78ebf94a6e778b6c8] in master [{{add6f81}}|https://github.com/apache/flink/commit/add6f810b7aa4c60550ab288bb9593fe92ee7189] in release-2.0 > update log4j to 2.24.3 to fix critical vulnerabilities > ------------------------------------------------------- > > Key: FLINK-37810 > URL: https://issues.apache.org/jira/browse/FLINK-37810 > Project: Flink > Issue Type: Technical Debt > Affects Versions: 2.0.0, 1.20.1 > Reporter: david radley > Assignee: david radley > Priority: Major > Labels: pull-request-available > Fix For: 1.20.2, 2.0.1 > > > flink Master and v2 are at 2.24.1 but there are 2 critical issues at that > level. > See [2.24.3 release notes |#release-notes-2-24-3]] for details. Update log4j > to 2.24.3 to resolve those issues. > > PR available > [https://github.com/apache/flink/pull/26570|https://github.com/apache/flink/pull/26570)] -- This message was sent by Atlassian Jira (v8.20.10#820010)