[D] CVE-2021-45046/GHSA-7rjr-3q55-vv33 backport to 2.3.x i s not reported on GHSA advisory [logging-log4j2]

noren95 (via GitHub) <[email protected]> Tue, 04 Aug 2026 07:50:55 -0000
Newsgroups gmane.comp.jakarta.log4j.devel
Message-ID <ghd-D_kwDOAKJSSM4AoPmh__14631.080375851$1785829867$gmane$org@gitbox.apache.org>
GitHub user noren95 created a discussion: CVE-2021-45046/GHSA-7rjr-3q55-vv33 backport to 2.3.x is not reported on GHSA advisory

Hi log4j team -
I was invetigating this CVE's affected scope, and I've noticed that the fix was backported to 2.3.x branch. 

Log4j advisory reports its fixed in 2.3.1. https://logging.apache.org/security.html#CVE-2021-45046
Also reflected in changelog https://github.com/apache/logging-log4j2/compare/rel/2.3...rel/2.3.1

This is not reflected in the GHSA affected range, and raises False Positive on dependency scanning.
I have opened this PR on GHSA but haven't got a response yet - could someone please confirm this?
https://github.com/github/advisory-database/pull/8692

I appreciate you help, thank you!

GitHub link: https://github.com/apache/logging-log4j2/discussions/4236

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]