diff options
author | Dan Timoney <dtimoney@att.com> | 2022-01-03 16:44:03 -0500 |
---|---|---|
committer | Dan Timoney <dtimoney@att.com> | 2022-01-03 16:44:03 -0500 |
commit | f3f03daaa608a0db54049765f767a275237dbaf0 (patch) | |
tree | 16b70e3f00af7caca2f08ee6d392f3755d6d6afa | |
parent | ab5bfc93c00d7e16e54730374e9fec84d91e0c16 (diff) |
Upgrade to log4j2 2.17.1
Update to use version 2.17.1 to resolve log4shell vulnerability
Issue-ID: CCSDK-3556
Signed-off-by: Dan Timoney <dtimoney@att.com>
Change-Id: I26727d116f066f4041e374d06b894223a86c96a4
-rw-r--r-- | dependencies-bom/pom.xml | 4 | ||||
-rw-r--r-- | installed-odl-bom/pom.xml | 6 | ||||
-rw-r--r-- | odlparent/binding-parent/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/bundle-parent/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/feature-repo-parent/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/karaf4-parent/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/mdsal-it-parent/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/odlparent-lite/pom.xml | 4 | ||||
-rw-r--r-- | odlparent/odlparent/pom.xml | 4 | ||||
-rwxr-xr-x | odlparent/setup/src/main/resources/pom-template.xml | 4 | ||||
-rw-r--r-- | odlparent/single-feature-parent/pom.xml | 4 | ||||
-rwxr-xr-x | oparent/pom.xml | 4 | ||||
-rw-r--r-- | springboot/spring-boot-setup/src/main/resources/pom-template.xml | 17 | ||||
-rw-r--r-- | springboot/springboot1/pom.xml | 17 | ||||
-rw-r--r-- | springboot/springboot2/pom.xml | 17 | ||||
-rw-r--r-- | springboot/springboot25/pom.xml | 4 | ||||
-rwxr-xr-x | standalone/pom.xml | 16 |
17 files changed, 82 insertions, 39 deletions
diff --git a/dependencies-bom/pom.xml b/dependencies-bom/pom.xml index b82fe7cd..cebfd4fa 100644 --- a/dependencies-bom/pom.xml +++ b/dependencies-bom/pom.xml @@ -211,12 +211,12 @@ <dependency> <groupId>org.apache.logging.log4j</groupId> <artifactId>log4j-slf4j-impl</artifactId> - <version>2.11.2</version> + <version>2.17.1</version> </dependency> <dependency> <groupId>org.apache.logging.log4j</groupId> <artifactId>log4j-core</artifactId> - <version>2.16.0</version> + <version>2.17.1</version> </dependency> <dependency> <groupId>org.apache.tomcat</groupId> diff --git a/installed-odl-bom/pom.xml b/installed-odl-bom/pom.xml index 7c275d54..1af4fb88 100644 --- a/installed-odl-bom/pom.xml +++ b/installed-odl-bom/pom.xml @@ -4179,17 +4179,17 @@ <dependency> <groupId>org.ops4j.pax.logging</groupId> <artifactId>pax-logging-api</artifactId> - <version>2.0.9</version> + <version>2.0.14</version> </dependency> <dependency> <groupId>org.ops4j.pax.logging</groupId> <artifactId>pax-logging-log4j2</artifactId> - <version>2.0.9</version> + <version>2.0.14</version> </dependency> <dependency> <groupId>org.ops4j.pax.logging</groupId> <artifactId>pax-logging-logback</artifactId> - <version>2.0.9</version> + <version>2.0.14</version> </dependency> <dependency> <groupId>org.ops4j.pax.tipi</groupId> diff --git a/odlparent/binding-parent/pom.xml b/odlparent/binding-parent/pom.xml index b104043b..84c3fd5f 100644 --- a/odlparent/binding-parent/pom.xml +++ b/odlparent/binding-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/bundle-parent/pom.xml b/odlparent/bundle-parent/pom.xml index 0db4943f..17dd130c 100644 --- a/odlparent/bundle-parent/pom.xml +++ b/odlparent/bundle-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/feature-repo-parent/pom.xml b/odlparent/feature-repo-parent/pom.xml index aa1ff0bf..8d6435b5 100644 --- a/odlparent/feature-repo-parent/pom.xml +++ b/odlparent/feature-repo-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/karaf4-parent/pom.xml b/odlparent/karaf4-parent/pom.xml index 9174fb12..ef6ee2f0 100644 --- a/odlparent/karaf4-parent/pom.xml +++ b/odlparent/karaf4-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/mdsal-it-parent/pom.xml b/odlparent/mdsal-it-parent/pom.xml index 9aa9bf45..366f9a7b 100644 --- a/odlparent/mdsal-it-parent/pom.xml +++ b/odlparent/mdsal-it-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/odlparent-lite/pom.xml b/odlparent/odlparent-lite/pom.xml index b940ce20..2170829f 100644 --- a/odlparent/odlparent-lite/pom.xml +++ b/odlparent/odlparent-lite/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/odlparent/pom.xml b/odlparent/odlparent/pom.xml index 088ce40c..5c5596f5 100644 --- a/odlparent/odlparent/pom.xml +++ b/odlparent/odlparent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/setup/src/main/resources/pom-template.xml b/odlparent/setup/src/main/resources/pom-template.xml index d5db22f3..2cce0878 100755 --- a/odlparent/setup/src/main/resources/pom-template.xml +++ b/odlparent/setup/src/main/resources/pom-template.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/odlparent/single-feature-parent/pom.xml b/odlparent/single-feature-parent/pom.xml index 846f2870..0a3c1473 100644 --- a/odlparent/single-feature-parent/pom.xml +++ b/odlparent/single-feature-parent/pom.xml @@ -176,8 +176,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.21.1</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <testng.version>6.14.3</testng.version> diff --git a/oparent/pom.xml b/oparent/pom.xml index 9f10ca43..4b1df011 100755 --- a/oparent/pom.xml +++ b/oparent/pom.xml @@ -77,8 +77,8 @@ <ccsdk.sli.plugins.version>${ccsdk.sli.version}</ccsdk.sli.plugins.version> <ccsdk.distribution.version>1.2.2-SNAPSHOT</ccsdk.distribution.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <fasterxml.jackson.version>2.10.5</fasterxml.jackson.version> <velocity.version>2.3</velocity.version> diff --git a/springboot/spring-boot-setup/src/main/resources/pom-template.xml b/springboot/spring-boot-setup/src/main/resources/pom-template.xml index 7104d384..d094231f 100644 --- a/springboot/spring-boot-setup/src/main/resources/pom-template.xml +++ b/springboot/spring-boot-setup/src/main/resources/pom-template.xml @@ -124,8 +124,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.25.0</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <netty-ssl>${springboot.netty.ssl.version}</netty-ssl> <protobuff.java.version>3.10.0</protobuff.java.version> <protobuff.java.utils.version>3.10.0</protobuff.java.utils.version> @@ -202,7 +202,18 @@ <groupId>org.liquibase</groupId> <artifactId>liquibase-core</artifactId> <version>4.4.2-nordix</version> - </dependency> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-api</artifactId> + <version>${log4j2.version}</version> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-core</artifactId> + <version>${log4j2.version}</version> + </dependency> + </dependencies> </dependencyManagement> diff --git a/springboot/springboot1/pom.xml b/springboot/springboot1/pom.xml index 773d041e..68faea70 100644 --- a/springboot/springboot1/pom.xml +++ b/springboot/springboot1/pom.xml @@ -124,8 +124,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.25.0</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <netty-ssl>2.0.39.Final</netty-ssl> <protobuff.java.version>3.10.0</protobuff.java.version> <protobuff.java.utils.version>3.10.0</protobuff.java.utils.version> @@ -202,7 +202,18 @@ <groupId>org.liquibase</groupId> <artifactId>liquibase-core</artifactId> <version>4.4.2-nordix</version> - </dependency> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-api</artifactId> + <version>${log4j2.version}</version> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-core</artifactId> + <version>${log4j2.version}</version> + </dependency> + </dependencies> </dependencyManagement> diff --git a/springboot/springboot2/pom.xml b/springboot/springboot2/pom.xml index 290f34b5..5503c80e 100644 --- a/springboot/springboot2/pom.xml +++ b/springboot/springboot2/pom.xml @@ -124,8 +124,8 @@ <derby.version>10.14.2.0</derby.version> <eelf.version>1.0.0</eelf.version> <grpc.version>1.25.0</grpc.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <netty-ssl>2.0.39.Final</netty-ssl> <protobuff.java.version>3.10.0</protobuff.java.version> <protobuff.java.utils.version>3.10.0</protobuff.java.utils.version> @@ -202,7 +202,18 @@ <groupId>org.liquibase</groupId> <artifactId>liquibase-core</artifactId> <version>4.4.2-nordix</version> - </dependency> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-api</artifactId> + <version>${log4j2.version}</version> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-core</artifactId> + <version>${log4j2.version}</version> + </dependency> + </dependencies> </dependencyManagement> diff --git a/springboot/springboot25/pom.xml b/springboot/springboot25/pom.xml index 5752dfd6..aa2fdf3f 100644 --- a/springboot/springboot25/pom.xml +++ b/springboot/springboot25/pom.xml @@ -129,8 +129,8 @@ <jettison.version>1.3.8</jettison.version> <logback.version>1.2.3</logback.version> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.3</mariadb.connector.version> <mariadb4j.version>2.4.0</mariadb4j.version> <slf4j.version>1.7.32</slf4j.version> diff --git a/standalone/pom.xml b/standalone/pom.xml index c549eeae..3bc2fb58 100755 --- a/standalone/pom.xml +++ b/standalone/pom.xml @@ -65,8 +65,8 @@ <bundle.plugin.version>2.5.0</bundle.plugin.version> <checkstyle.skip>true</checkstyle.skip> - <log4j.version>2.16.0</log4j.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j.version>2.17.1</log4j.version> + <log4j2.version>2.17.1</log4j2.version> <mariadb.connector.version>2.7.2</mariadb.connector.version> <fasterxml.jackson.version>2.12.4</fasterxml.jackson.version> <velocity.version>2.3</velocity.version> @@ -103,8 +103,18 @@ </dependency> <dependency> <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-api</artifactId> + <version>2.17.1</version> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> + <artifactId>log4j-core</artifactId> + <version>2.17.1</version> + </dependency> + <dependency> + <groupId>org.apache.logging.log4j</groupId> <artifactId>log4j-slf4j-impl</artifactId> - <version>2.11.2</version> + <version>2.17.1</version> </dependency> <dependency> <groupId>com.fasterxml.jackson.core</groupId> |