Upgrade to log4j2 2.17.1
Upgrade to log4j2 version 2.17.1 to correct log4shell vulnerability
Issue-ID: CCSDK-3556
Signed-off-by: Dan Timoney <dtimoney@att.com>
Change-Id: I61a3fdd9854a1beee70abed1fd8542cdf664756a
diff --git a/springboot/springboot2/pom.xml b/springboot/springboot2/pom.xml
index f0b4974..644055e 100644
--- a/springboot/springboot2/pom.xml
+++ b/springboot/springboot2/pom.xml
@@ -130,8 +130,8 @@
<jersey.version>2.30.1</jersey.version>
<jersey.client.version>2.30.1</jersey.client.version>
<jettison.version>1.3.8</jettison.version>
- <log4j.version>2.16.0</log4j.version>
- <log4j2.version>2.16.0</log4j2.version>
+ <log4j.version>2.17.1</log4j.version>
+ <log4j2.version>2.17.1</log4j2.version>
<logback.version>1.2.3</logback.version>
<mariadb.connector.version>2.7.3</mariadb.connector.version>
<mariadb4j.version>2.4.0</mariadb4j.version>