Update Log4j to 1.2.17-atlassian-16 to fix CVE-2022-23305, CVE-2022-23307, CVE-2020-9493, CVE-2022-23302

XMLWordPrintable

    • 8.1
    • High
    • CVE-2022-23305

      Crucible in version 4.8.9 and older uses a log4j library that has the following vulnerabilities:

      • CVE-2022-23302
      • CVE-2022-23305
      • CVE-2022-23307 / CVE-2020-9493

      Crucible 4.8.10 uses a custom-built log4j, which has the above vulnerabilities fixed.

            Assignee:
            Unassigned
            Reporter:
            Security Metrics Bot
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: