Details
-
Suggestion
-
Status: Not Being Considered
-
Resolution: Duplicate
-
None
-
None
Description
Xray should use the upgraded log4j version 2.
Currently, we use the Atlassian forked version for Log4j is a dependency and it is showing false errors on the security scans. To remove this, we should upgrade to V2
Attachments
Issue Links
- duplicates
-
XRAY-9963 Vulnerabilities in 1.2.x log4j library
- Closed