Skip to content

Log4j vulnerability in some sample projects #32

@LentilHead

Description

@LentilHead

It seems to me like some of the provided sample projects depend on a vulnerable log4j version.
The oauth2-server which is used in several chapters loads log4j version 2.12.1 for example.
I think you might want to consider mitigating 1 this vulnerability, even though these projects are only intended for teaching purposes.

Footnotes

  1. Log4J2 Vulnerability and Spring Boot

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions