| Summary: | log4j, log4j12 new security issue CVE-2020-9488 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | mageia |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | log4j-2.11.1-1.mga7.src.rpm, log4j12-1.2.17-19.mga7.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 2.13.2, log4j12 also needs to be patched | ||
|
Description
David Walser
2020-04-26 01:57:33 CEST
David Walser
2020-04-26 01:57:40 CEST
Whiteboard:
(none) =>
MGA7TOO log4j has been updated to 2.13.3 in Cauldron, fixing this, but log4j12 is still vulnerable. Source RPM:
log4j-2.11.1-2.mga8.src.rpm, log4j12-1.2.17-20.mga8.src.rpm =>
log4j-2.11.1-1.mga7.src.rpm, log4j12-1.2.17-19.mga7.src.rpm
David Walser
2020-12-27 18:41:00 CET
Status comment:
(none) =>
Fixed upstream in 2.13.2, log4j12 also needs to be patched not in cauldron anymore CC:
(none) =>
mageia log4j12-1.2.17-21.mga8.noarch.rpm log4j12-javadoc-1.2.17-21.mga8.noarch.rpm are still there unfortunately. Version:
7 =>
Cauldron not anymore ;-) wait for your mirror to be synced. Whiteboard:
MGA7TOO =>
(none) https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Resolution:
(none) =>
OLD |