Upgrade log4j to version 2.15.0 16/126216/2
authorDan Timoney <dtimoney@att.com>
Mon, 13 Dec 2021 20:59:55 +0000 (15:59 -0500)
committerDan Timoney <dtimoney@att.com>
Tue, 14 Dec 2021 12:35:41 +0000 (07:35 -0500)
Update log4j version to address known vulnerability

Issue-ID: CCSDK-3556
Signed-off-by: Dan Timoney <dtimoney@att.com>
Change-Id: Ie0840a7f45257092c93bd5dbb23d197a1de491b0

15 files changed:
dependencies-bom/pom.xml
odlparent/binding-parent/pom.xml
odlparent/bundle-parent/pom.xml
odlparent/feature-repo-parent/pom.xml
odlparent/karaf4-parent/pom.xml
odlparent/mdsal-it-parent/pom.xml
odlparent/odlparent-lite/pom.xml
odlparent/odlparent/pom.xml
odlparent/setup/src/main/resources/pom-template.xml
odlparent/single-feature-parent/pom.xml
oparent/pom.xml
springboot/spring-boot-setup/src/main/resources/pom-template.xml
springboot/springboot1/pom.xml
springboot/springboot2/pom.xml
standalone/pom.xml

index 728c60f..ca1b475 100644 (file)
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-slf4j-impl</artifactId>
-                <version>2.11.2</version>
+                <version>2.15.0</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-core</artifactId>
-                <version>2.14.1</version>
+                <version>2.15.0</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.tomcat</groupId>
index 30a4638..f9e9812 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index a55e5f2..80eef04 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index 21acb34..6adf57c 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index 0540b64..909d343 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index 1c16dee..ff3dbd8 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index b8d7a7c..2e06a05 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index f943dfc..b6a21df 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index cd5b259..acd3942 100755 (executable)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index 810ca4f..25d5479 100644 (file)
         <derby.version>10.14.2.0</derby.version>
         <eelf.version>1.0.0</eelf.version>
         <grpc.version>1.21.1</grpc.version>
+        <jetty.version>9.4.40.v20210413</jetty.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
         <testng.version>6.14.3</testng.version>
         <tomcat-jdbc.version>9.0.52</tomcat-jdbc.version>
-        <jetty.version>9.4.40.v20210413</jetty.version>
+        
         <skip.karaf.featureTest>true</skip.karaf.featureTest>
         <dependency-list.file>direct-dependencies.txt</dependency-list.file>
     </properties>
index f300f9c..2806936 100755 (executable)
@@ -77,6 +77,8 @@
         <ccsdk.sli.plugins.version>${ccsdk.sli.version}</ccsdk.sli.plugins.version>
         <ccsdk.distribution.version>1.1.1-SNAPSHOT</ccsdk.distribution.version>
 
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <fasterxml.jackson.version>2.10.5</fasterxml.jackson.version>
         <velocity.version>2.3</velocity.version>
index 0271683..25b5276 100644 (file)
         <jersey.version>${springboot.jersey.version}</jersey.version>
         <jersey.client.version>${springboot.jersey.version}</jersey.client.version>
         <jettison.version>1.3.8</jettison.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <logback.version>1.2.3</logback.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
index 669736e..81ae572 100644 (file)
         <jersey.version>2.30.1</jersey.version>
         <jersey.client.version>2.30.1</jersey.client.version>
         <jettison.version>1.3.8</jettison.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <logback.version>1.2.3</logback.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
index 4451ccf..0915673 100644 (file)
         <jersey.version>2.30.1</jersey.version>
         <jersey.client.version>2.30.1</jersey.client.version>
         <jettison.version>1.3.8</jettison.version>
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <logback.version>1.2.3</logback.version>
         <mariadb.connector.version>2.7.3</mariadb.connector.version>
         <mariadb4j.version>2.4.0</mariadb4j.version>
index e0faa1e..da8c76e 100755 (executable)
@@ -65,6 +65,8 @@
         <bundle.plugin.version>2.5.0</bundle.plugin.version>
         <checkstyle.skip>true</checkstyle.skip>
 
+        <log4j.version>2.15.0</log4j.version>
+        <log4j2.version>2.15.0</log4j2.version>
         <mariadb.connector.version>2.7.2</mariadb.connector.version>
         <fasterxml.jackson.version>2.12.4</fasterxml.jackson.version>
         <velocity.version>2.3</velocity.version>
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-slf4j-impl</artifactId>
-                <version>2.11.2</version>
+                <version>2.15.0</version>
             </dependency>
             <dependency>
                 <groupId>com.fasterxml.jackson.core</groupId>