diff --git a/vdr.xml b/vdr.xml index 98807dca..110dc499 100644 --- a/vdr.xml +++ b/vdr.xml @@ -15,7 +15,6 @@ ~ See the License for the specific language governing permissions and ~ limitations under the License. --> - + + 2025-08-17T11:18:06Z + + Apache Logging Services + https://logging.apache.org + + + @@ -76,24 +89,24 @@ - 2021-12-28T00:00:00Z 2021-12-28T00:00:00Z - 2022-08-08T00:00:00Z + 2025-08-17T11:18:06Z pkg:maven/org.apache.logging.log4j/log4j-core?type=jar - =2.0-beta7|<2.3.2]]> + =2.0-beta7|<2.3.1]]> - =2.4|<2.12.4]]> + =2.4|<2.12.3]]> - =2.13.0|<2.17.1]]> + =2.13.0|<2.17.0]]> @@ -210,10 +223,10 @@ Remote code execution has been demonstrated on macOS, Fedora, Arch Linux, and Al Note that this vulnerability is not limited to just the JNDI lookup. Any other Lookup could also be included in a Thread Context Map variable and possibly have private details exposed to anyone with access to the logs.]]> - + 2021-12-14T00:00:00Z 2021-12-14T00:00:00Z - 2023-10-26T00:00:00Z + 2025-08-17T11:18:06Z @@ -250,7 +263,7 @@ Any other Lookup could also be included in a Thread Context Map variable and pos =2.4|<2.12.3]]> - =2.13.0|<2.17.0]]> + =2.13.0|<2.16.0]]> @@ -299,10 +312,10 @@ Any other Lookup could also be included in a Thread Context Map variable and pos - + 2021-12-10T00:00:00Z 2021-12-10T00:00:00Z - 2023-04-03T00:00:00Z + 2025-08-17T11:18:06Z @@ -318,10 +331,10 @@ An attacker who can control log messages or log message parameters can execute a =2.0-beta9|<2.3.1]]> - =2.4|<2.12.3]]> + =2.4|<2.12.2]]> - =2.13.0|<2.17.0]]> + =2.13.0|<2.15.0]]> @@ -366,12 +379,12 @@ The reported issue was caused by an error in `SslConfiguration`. Any element using `SslConfiguration` in the Log4j `Configuration` is also affected by this issue. This includes `HttpAppender`, `SocketAppender`, and `SyslogAppender`. Usages of `SslConfiguration` that are configured via system properties are not affected.]]> - 2017-04-27T00:00:00Z 2017-04-27T00:00:00Z - 2022-05-12T00:00:00Z + 2025-08-17T11:18:06Z @@ -384,10 +397,13 @@ Alternatively, users can set the `mail.smtp.ssl.checkserveridentity` system prop pkg:maven/org.apache.logging.log4j/log4j-core?type=jar - =2.0-beta1|<2.12.3]]> + =2.0-beta1|<2.3.2]]> + + + =2.4|<2.12.3]]> - + =2.13.0|<2.13.2]]>