Update log4j version due to security vulnerability 76/126476/1
authorliamfallon <liam.fallon@est.tech>
Wed, 5 Jan 2022 12:49:37 +0000 (12:49 +0000)
committerliamfallon <liam.fallon@est.tech>
Wed, 5 Jan 2022 12:49:41 +0000 (12:49 +0000)
SECCOM has recommended going to log4j 2.17.1.

Issue-ID: POLICY-3862
Change-Id: I486d89bc467f92c4ac8f43b57b3829aa459fc550
Signed-off-by: liamfallon <liam.fallon@est.tech>
integration/pom.xml

index 6053e61..a02a3ea 100644 (file)
@@ -2,7 +2,7 @@
   ============LICENSE_START=======================================================
    Copyright (C) 2018 Ericsson. All rights reserved.
    Modifications Copyright (C) 2018-2021 AT&T. All rights reserved.
-   Modifications Copyright (C) 2019-2021 Nordix Foundation.
+   Modifications Copyright (C) 2019-2022 Nordix Foundation.
    Modifications Copyright (C) 2020-2021 Bell Canada.
   ================================================================================
   Licensed under the Apache License, Version 2.0 (the "License");
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-api</artifactId>
-                <version>2.16.0</version>
+                <version>2.17.1</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>