[D] CVE-2021-45046/GHSA-7rjr-3q55-vv33 backport to 2.3.x i s not reported on GHSA advisory [logging-log4j2]
noren95 (via GitHub) <[email protected]> Tue, 04 Aug 2026 07:50:55 -0000
| Newsgroups | gmane.comp.jakarta.log4j.devel |
|---|---|
| Message-ID | <ghd-D_kwDOAKJSSM4AoPmh__14631.080375851$1785829867$gmane$org@gitbox.apache.org> |
GitHub user noren95 created a discussion: CVE-2021-45046/GHSA-7rjr-3q55-vv33 backport to 2.3.x is not reported on GHSA advisory Hi log4j team - I was invetigating this CVE's affected scope, and I've noticed that the fix was backported to 2.3.x branch. Log4j advisory reports its fixed in 2.3.1. https://logging.apache.org/security.html#CVE-2021-45046 Also reflected in changelog https://github.com/apache/logging-log4j2/compare/rel/2.3...rel/2.3.1 This is not reflected in the GHSA affected range, and raises False Positive on dependency scanning. I have opened this PR on GHSA but haven't got a response yet - could someone please confirm this? https://github.com/github/advisory-database/pull/8692 I appreciate you help, thank you! GitHub link: https://github.com/apache/logging-log4j2/discussions/4236 ---- This is an automatically sent email for [email protected]. To unsubscribe, please send an email to: [email protected]