Skip to content

Conversation

@m1a2st
Copy link
Collaborator

@m1a2st m1a2st commented Jan 6, 2026

Updated lo4j2 version to 2.25.3 to prevent CVE. FYI:
https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core

CVE LINK : https://nvd.nist.gov/vuln/detail/CVE-2025-68161

Reviewers: Chia-Ping Tsai [email protected]

@github-actions github-actions bot added triage PRs from the community build Gradle build or GitHub Actions small Small PRs dependencies Pull requests that update a dependency file labels Jan 6, 2026
@m1a2st m1a2st force-pushed the KAFKA-20038 branch 4 times, most recently from b97c54f to 66b6ebf Compare January 6, 2026 12:35
@chia7712 chia7712 changed the title KAFKA-20038 [CVE-2025-68161] [log4j-core] [2.17.1][Kafka] KAFKA-20038 Upgrade Log4j to 2.25.3 to fix CVE-2025-68161 Jan 7, 2026
@chia7712 chia7712 merged commit 84fa531 into apache:trunk Jan 7, 2026
25 checks passed
chia7712 pushed a commit that referenced this pull request Jan 7, 2026
@github-actions github-actions bot removed the triage PRs from the community label Jan 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build Gradle build or GitHub Actions dependencies Pull requests that update a dependency file small Small PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants