Skip to content

Commit da56a2a

Browse files
rohityadavcloudmlsorensenMarcus Sorensen
authored
maven: migrate short-term to reload4j v1.2.18 (#5878)
* maven: migrate short-term to reload4j v1.2.18 This migrate to log4j 1.x fork, reload4j 1.2.18.0 which is drop-in replacement and addresses some immediate CVE and issues. * log4j migration to reload4j in pom xmls Signed-off-by: Rohit Yadav <[email protected]> * Exclude log4j from transitive dependencies (#73) Co-authored-by: Marcus Sorensen <[email protected]> Co-authored-by: Marcus Sorensen <[email protected]>
1 parent af58284 commit da56a2a

File tree

12 files changed

+44
-24
lines changed

12 files changed

+44
-24
lines changed

framework/managed-context/pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,9 @@
2929
</parent>
3030
<dependencies>
3131
<dependency>
32-
<groupId>log4j</groupId>
33-
<artifactId>log4j</artifactId>
34-
<version>${cs.log4j.version}</version>
32+
<groupId>ch.qos.reload4j</groupId>
33+
<artifactId>reload4j</artifactId>
34+
<version>${cs.reload4j.version}</version>
3535
</dependency>
3636
</dependencies>
3737
</project>

plugins/alert-handlers/snmp-alerts/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,8 @@
3333
<artifactId>org.apache.servicemix.bundles.snmp4j</artifactId>
3434
</dependency>
3535
<dependency>
36-
<groupId>log4j</groupId>
37-
<artifactId>log4j</artifactId>
36+
<groupId>ch.qos.reload4j</groupId>
37+
<artifactId>reload4j</artifactId>
3838
</dependency>
3939
</dependencies>
4040
</project>

plugins/alert-handlers/syslog-alerts/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,8 @@
2929
</parent>
3030
<dependencies>
3131
<dependency>
32-
<groupId>log4j</groupId>
33-
<artifactId>log4j</artifactId>
32+
<groupId>ch.qos.reload4j</groupId>
33+
<artifactId>reload4j</artifactId>
3434
</dependency>
3535
</dependencies>
3636
</project>

plugins/hypervisors/ovm3/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,8 +44,8 @@
4444
<version>${cs.commons-lang3.version}</version>
4545
</dependency>
4646
<dependency>
47-
<groupId>log4j</groupId>
48-
<artifactId>log4j</artifactId>
47+
<groupId>ch.qos.reload4j</groupId>
48+
<artifactId>reload4j</artifactId>
4949
</dependency>
5050
</dependencies>
5151
<build>

plugins/integrations/kubernetes-service/pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -86,9 +86,9 @@
8686
<version>${cs.guava.version}</version>
8787
</dependency>
8888
<dependency>
89-
<groupId>log4j</groupId>
90-
<artifactId>log4j</artifactId>
91-
<version>${cs.log4j.version}</version>
89+
<groupId>ch.qos.reload4j</groupId>
90+
<artifactId>reload4j</artifactId>
91+
<version>${cs.reload4j.version}</version>
9292
</dependency>
9393
<dependency>
9494
<groupId>org.springframework</groupId>

plugins/network-elements/juniper-contrail/pom.xml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -112,6 +112,12 @@
112112
<groupId>net.juniper.contrail</groupId>
113113
<artifactId>juniper-contrail-api</artifactId>
114114
<version>1.0-SNAPSHOT</version>
115+
<exclusions>
116+
<exclusion>
117+
<artifactId>log4j</artifactId>
118+
<groupId>log4j</groupId>
119+
</exclusion>
120+
</exclusions>
115121
</dependency>
116122
<dependency>
117123
<groupId>mysql</groupId>

plugins/user-authenticators/ldap/pom.xml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -175,6 +175,10 @@
175175
<version>${ads.version}</version>
176176
<scope>test</scope>
177177
<exclusions>
178+
<exclusion>
179+
<artifactId>log4j</artifactId>
180+
<groupId>log4j</groupId>
181+
</exclusion>
178182
<!--
179183
shared-ldap-schema module needs to be excluded to avoid multiple schema resources on the classpath
180184
-->

pom.xml

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,7 @@
7676
<cs.clover-maven-plugin.version>4.4.1</cs.clover-maven-plugin.version>
7777

7878
<!-- Logging versions -->
79-
<cs.log4j.version>1.2.17</cs.log4j.version>
79+
<cs.reload4j.version>1.2.18.4</cs.reload4j.version>
8080
<cs.log4j.extras.version>1.2.17</cs.log4j.extras.version>
8181
<cs.logging.version>1.1.1</cs.logging.version>
8282

@@ -439,9 +439,9 @@
439439
</exclusions>
440440
</dependency>
441441
<dependency>
442-
<groupId>log4j</groupId>
443-
<artifactId>log4j</artifactId>
444-
<version>${cs.log4j.version}</version>
442+
<groupId>ch.qos.reload4j</groupId>
443+
<artifactId>reload4j</artifactId>
444+
<version>${cs.reload4j.version}</version>
445445
</dependency>
446446
<dependency>
447447
<groupId>mysql</groupId>
@@ -618,6 +618,12 @@
618618
<groupId>org.owasp.esapi</groupId>
619619
<artifactId>esapi</artifactId>
620620
<version>2.1.0.1</version>
621+
<exclusions>
622+
<exclusion>
623+
<groupId>log4j</groupId>
624+
<artifactId>log4j</artifactId>
625+
</exclusion>
626+
</exclusions>
621627
</dependency>
622628
<!-- Test dependency in mysql for db tests -->
623629
<dependency>

services/console-proxy/server/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,8 @@
2929
</parent>
3030
<dependencies>
3131
<dependency>
32-
<groupId>log4j</groupId>
33-
<artifactId>log4j</artifactId>
32+
<groupId>ch.qos.reload4j</groupId>
33+
<artifactId>reload4j</artifactId>
3434
</dependency>
3535
<dependency>
3636
<groupId>com.google.code.gson</groupId>

services/secondary-storage/server/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,8 @@
2929
</parent>
3030
<dependencies>
3131
<dependency>
32-
<groupId>log4j</groupId>
33-
<artifactId>log4j</artifactId>
32+
<groupId>ch.qos.reload4j</groupId>
33+
<artifactId>reload4j</artifactId>
3434
</dependency>
3535
<dependency>
3636
<groupId>com.google.code.gson</groupId>

0 commit comments

Comments
 (0)