Update log4j version due to security vulnerability for NCMP-DMI 87/126287/1
authorniamhcore <niamh.core@est.tech>
Wed, 15 Dec 2021 11:23:56 +0000 (11:23 +0000)
committerNiamh Core <niamh.core@est.tech>
Thu, 16 Dec 2021 09:43:37 +0000 (09:43 +0000)
This change excludes old log4j libraries and includes newer versions
that are not tagged with a security vulnerability.

Issue-ID: CPS-820
Signed-off-by: niamhcore <niamh.core@est.tech>
Change-Id: I2694cdc66449a9634dfe726b39736a8b0ba67e5a
(cherry picked from commit 983510777aead2f8827c5f74fa54193884ef79aa)

pom.xml

diff --git a/pom.xml b/pom.xml
index d3e25b6..9b25862 100644 (file)
--- a/pom.xml
+++ b/pom.xml
                 <type>pom</type>
                 <scope>import</scope>
             </dependency>
+            <dependency>
+                <groupId>org.apache.logging.log4j</groupId>
+                <artifactId>log4j-api</artifactId>
+                <version>2.16.0</version>
+            </dependency>
+            <dependency>
+                <groupId>org.apache.logging.log4j</groupId>
+                <artifactId>log4j-to-slf4j</artifactId>
+                <version>2.16.0</version>
+            </dependency>
         </dependencies>
     </dependencyManagement>
     <dependencies>