From f3f03daaa608a0db54049765f767a275237dbaf0 Mon Sep 17 00:00:00 2001 From: Dan Timoney Date: Mon, 3 Jan 2022 16:44:03 -0500 Subject: [PATCH] Upgrade to log4j2 2.17.1 Update to use version 2.17.1 to resolve log4shell vulnerability Issue-ID: CCSDK-3556 Signed-off-by: Dan Timoney Change-Id: I26727d116f066f4041e374d06b894223a86c96a4 --- dependencies-bom/pom.xml | 4 ++-- installed-odl-bom/pom.xml | 6 +++--- odlparent/binding-parent/pom.xml | 4 ++-- odlparent/bundle-parent/pom.xml | 4 ++-- odlparent/feature-repo-parent/pom.xml | 4 ++-- odlparent/karaf4-parent/pom.xml | 4 ++-- odlparent/mdsal-it-parent/pom.xml | 4 ++-- odlparent/odlparent-lite/pom.xml | 4 ++-- odlparent/odlparent/pom.xml | 4 ++-- odlparent/setup/src/main/resources/pom-template.xml | 4 ++-- odlparent/single-feature-parent/pom.xml | 4 ++-- oparent/pom.xml | 4 ++-- .../src/main/resources/pom-template.xml | 17 ++++++++++++++--- springboot/springboot1/pom.xml | 17 ++++++++++++++--- springboot/springboot2/pom.xml | 17 ++++++++++++++--- springboot/springboot25/pom.xml | 4 ++-- standalone/pom.xml | 16 +++++++++++++--- 17 files changed, 82 insertions(+), 39 deletions(-) diff --git a/dependencies-bom/pom.xml b/dependencies-bom/pom.xml index b82fe7cd..cebfd4fa 100644 --- a/dependencies-bom/pom.xml +++ b/dependencies-bom/pom.xml @@ -211,12 +211,12 @@ org.apache.logging.log4j log4j-slf4j-impl - 2.11.2 + 2.17.1 org.apache.logging.log4j log4j-core - 2.16.0 + 2.17.1 org.apache.tomcat diff --git a/installed-odl-bom/pom.xml b/installed-odl-bom/pom.xml index 7c275d54..1af4fb88 100644 --- a/installed-odl-bom/pom.xml +++ b/installed-odl-bom/pom.xml @@ -4179,17 +4179,17 @@ org.ops4j.pax.logging pax-logging-api - 2.0.9 + 2.0.14 org.ops4j.pax.logging pax-logging-log4j2 - 2.0.9 + 2.0.14 org.ops4j.pax.logging pax-logging-logback - 2.0.9 + 2.0.14 org.ops4j.pax.tipi diff --git a/odlparent/binding-parent/pom.xml b/odlparent/binding-parent/pom.xml index b104043b..84c3fd5f 100644 --- a/odlparent/binding-parent/pom.xml +++ b/odlparent/binding-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/bundle-parent/pom.xml b/odlparent/bundle-parent/pom.xml index 0db4943f..17dd130c 100644 --- a/odlparent/bundle-parent/pom.xml +++ b/odlparent/bundle-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/feature-repo-parent/pom.xml b/odlparent/feature-repo-parent/pom.xml index aa1ff0bf..8d6435b5 100644 --- a/odlparent/feature-repo-parent/pom.xml +++ b/odlparent/feature-repo-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/karaf4-parent/pom.xml b/odlparent/karaf4-parent/pom.xml index 9174fb12..ef6ee2f0 100644 --- a/odlparent/karaf4-parent/pom.xml +++ b/odlparent/karaf4-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/mdsal-it-parent/pom.xml b/odlparent/mdsal-it-parent/pom.xml index 9aa9bf45..366f9a7b 100644 --- a/odlparent/mdsal-it-parent/pom.xml +++ b/odlparent/mdsal-it-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/odlparent-lite/pom.xml b/odlparent/odlparent-lite/pom.xml index b940ce20..2170829f 100644 --- a/odlparent/odlparent-lite/pom.xml +++ b/odlparent/odlparent-lite/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/odlparent/pom.xml b/odlparent/odlparent/pom.xml index 088ce40c..5c5596f5 100644 --- a/odlparent/odlparent/pom.xml +++ b/odlparent/odlparent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/setup/src/main/resources/pom-template.xml b/odlparent/setup/src/main/resources/pom-template.xml index d5db22f3..2cce0878 100755 --- a/odlparent/setup/src/main/resources/pom-template.xml +++ b/odlparent/setup/src/main/resources/pom-template.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/odlparent/single-feature-parent/pom.xml b/odlparent/single-feature-parent/pom.xml index 846f2870..0a3c1473 100644 --- a/odlparent/single-feature-parent/pom.xml +++ b/odlparent/single-feature-parent/pom.xml @@ -176,8 +176,8 @@ 10.14.2.0 1.0.0 1.21.1 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 6.14.3 diff --git a/oparent/pom.xml b/oparent/pom.xml index 9f10ca43..4b1df011 100755 --- a/oparent/pom.xml +++ b/oparent/pom.xml @@ -77,8 +77,8 @@ ${ccsdk.sli.version} 1.2.2-SNAPSHOT - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.10.5 2.3 diff --git a/springboot/spring-boot-setup/src/main/resources/pom-template.xml b/springboot/spring-boot-setup/src/main/resources/pom-template.xml index 7104d384..d094231f 100644 --- a/springboot/spring-boot-setup/src/main/resources/pom-template.xml +++ b/springboot/spring-boot-setup/src/main/resources/pom-template.xml @@ -124,8 +124,8 @@ 10.14.2.0 1.0.0 1.25.0 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 ${springboot.netty.ssl.version} 3.10.0 3.10.0 @@ -202,7 +202,18 @@ org.liquibase liquibase-core 4.4.2-nordix - + + + org.apache.logging.log4j + log4j-api + ${log4j2.version} + + + org.apache.logging.log4j + log4j-core + ${log4j2.version} + + diff --git a/springboot/springboot1/pom.xml b/springboot/springboot1/pom.xml index 773d041e..68faea70 100644 --- a/springboot/springboot1/pom.xml +++ b/springboot/springboot1/pom.xml @@ -124,8 +124,8 @@ 10.14.2.0 1.0.0 1.25.0 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.0.39.Final 3.10.0 3.10.0 @@ -202,7 +202,18 @@ org.liquibase liquibase-core 4.4.2-nordix - + + + org.apache.logging.log4j + log4j-api + ${log4j2.version} + + + org.apache.logging.log4j + log4j-core + ${log4j2.version} + + diff --git a/springboot/springboot2/pom.xml b/springboot/springboot2/pom.xml index 290f34b5..5503c80e 100644 --- a/springboot/springboot2/pom.xml +++ b/springboot/springboot2/pom.xml @@ -124,8 +124,8 @@ 10.14.2.0 1.0.0 1.25.0 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.0.39.Final 3.10.0 3.10.0 @@ -202,7 +202,18 @@ org.liquibase liquibase-core 4.4.2-nordix - + + + org.apache.logging.log4j + log4j-api + ${log4j2.version} + + + org.apache.logging.log4j + log4j-core + ${log4j2.version} + + diff --git a/springboot/springboot25/pom.xml b/springboot/springboot25/pom.xml index 5752dfd6..aa2fdf3f 100644 --- a/springboot/springboot25/pom.xml +++ b/springboot/springboot25/pom.xml @@ -129,8 +129,8 @@ 1.3.8 1.2.3 - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.3 2.4.0 1.7.32 diff --git a/standalone/pom.xml b/standalone/pom.xml index c549eeae..3bc2fb58 100755 --- a/standalone/pom.xml +++ b/standalone/pom.xml @@ -65,8 +65,8 @@ 2.5.0 true - 2.16.0 - 2.16.0 + 2.17.1 + 2.17.1 2.7.2 2.12.4 2.3 @@ -101,10 +101,20 @@ slf4j-api 1.7.29 + + org.apache.logging.log4j + log4j-api + 2.17.1 + + + org.apache.logging.log4j + log4j-core + 2.17.1 + org.apache.logging.log4j log4j-slf4j-impl - 2.11.2 + 2.17.1 com.fasterxml.jackson.core -- 2.16.6