From 7a7882e462d2f69c521aabeefd0947080629c54d Mon Sep 17 00:00:00 2001 From: Tim Pavlik Date: Thu, 16 Dec 2021 08:43:07 -0800 Subject: [PATCH] Update log4j-core to 2.16 per CVE-2021-45046. --- CHANGELOG.md | 9 +++++++-- pom.xml | 4 ++-- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 853dc328..d46b14ca 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,9 +1,14 @@ # Splunk Logging for Java Changelog +## Version 1.11.2 + +### Critical Security Update +* Upgrading log4J to 2.16 per CVE-2021-45046. + ## Version 1.11.1 -### Minor Changes -* Upgrading log4J per CVE-2021-44228. [PR](https://github.com/splunk/splunk-library-javalogging/pull/222) +### Critical Security Update +* Upgrading log4J to 2.15 per CVE-2021-44228. [PR](https://github.com/splunk/splunk-library-javalogging/pull/222) ## Version 1.11.0 diff --git a/pom.xml b/pom.xml index 91e1048e..feb5bd87 100644 --- a/pom.xml +++ b/pom.xml @@ -5,7 +5,7 @@ com.splunk.logging splunk-library-javalogging - 1.11.1 + 1.11.2 jar Splunk Logging for Java @@ -221,7 +221,7 @@ org.apache.logging.log4j log4j-core provided - 2.15.0 + 2.16.0