Skip to content

CVE-2022-23302/23305/23307 In log4j(1.x) #497

@EchoLee117

Description

@EchoLee117

Hi
Recently,three vulnerabilities have been discovered :CVE-2022-23302/23305/23307 In log4j(1.x)
The module “ribbon-evcache”(used in Ribbon ) depend on log4j 1.2.17
So do we have any plans to deal with these vulnerabilities?
Thanks :)

https://www.cvedetails.com/cve/CVE-2022-23302
https://nvd.nist.gov/vuln/detail/CVE-2022-23305
https://nvd.nist.gov/vuln/detail/CVE-2022-23307

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions