← All tasks
javahazelcast/hazelcast #24170Not a task: already works

Vulnerabilities in log4j 1.2.17 used by hazelcast-sql [HZ-2241]

envgap__hazelcast__hazelcast-24170

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
53c24f50f530b4250a5b1dd0ab9253796ed34d28
Manifest
hazelcast-sql/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

hazelcast/hazelcast #24170 · read the original issue
`hazelcast-sql` in `5.1.z` stream uses `calcite-core` in version `1.28.0` which uses `com.google.uzaygezen:uzaygezen-core` in version `0.2` which uses `log4j` in version `1.2.17` which includes following vulnerabilities:

- CVE-2019-17571 - https://nvd.nist.gov/vuln/detail/CVE-2019-17571

- CVE-2021-4104 - https://nvd.nist.gov/vuln/detail/CVE-2021-4104

- CVE-2022-23302 - https://nvd.nist.gov/vuln/detail/CVE-2022-23302

- CVE-2022-23305 - https://nvd.nist.gov/vuln/detail/CVE-2022-23305

- CVE-2023-26464 - https://nvd.nist.gov/vuln/detail/CVE-2023-26464
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]