little-megabyte-1074
log4j vulnerability patch — we recommend everyone update to the latest version as soon as possible. Shoutout to @high-hospital-85984 for quickly pushing a fix teamwork
• Redshift lineage
• Incubating Mode integration
• & more!!
Check out the full write up here!stocky-television-65849
12/10/2021, 10:05 PMstocky-television-65849
12/10/2021, 10:22 PMbig-carpet-38439
12/10/2021, 10:31 PMplain-farmer-27314
12/10/2021, 10:54 PMlittle-megabyte-1074
early-lamp-41924
12/11/2021, 1:18 AMpolite-flower-25924
12/11/2021, 8:23 AMmillions-notebook-72121
12/13/2021, 10:39 AMelasticsearch-setup-job seems to be failing with the below - have you seen this before? I am using elasticsearch on AWS. Works fine if I revert to 0.8.17early-lamp-41924
12/13/2021, 10:46 AMmillions-notebook-72121
12/13/2021, 10:49 AMearly-lamp-41924
12/13/2021, 10:49 AMearly-lamp-41924
12/13/2021, 10:49 AMearly-lamp-41924
12/13/2021, 10:49 AMearly-lamp-41924
12/13/2021, 10:50 AMearly-lamp-41924
12/13/2021, 10:50 AMmillions-notebook-72121
12/13/2021, 11:19 AMbrainy-author-77356
12/13/2021, 1:05 PMearly-lamp-41924
12/13/2021, 2:16 PMearly-lamp-41924
12/13/2021, 2:18 PMearly-lamp-41924
12/13/2021, 2:19 PM-Dlog4j2.formatMsgNoLookups=truebrainy-author-77356
12/13/2021, 2:46 PMbrainy-author-77356
12/14/2021, 5:21 AMearly-lamp-41924
12/14/2021, 5:22 AMbrainy-author-77356
12/14/2021, 3:12 PM+--- org.springframework.boot:spring-boot-starter-cache:2.1.4.RELEASE
| +--- org.springframework.boot:spring-boot-starter:2.1.4.RELEASE
| | +--- org.springframework.boot:spring-boot:2.1.4.RELEASE (*)
| | +--- org.springframework.boot:spring-boot-autoconfigure:2.1.4.RELEASE (*)
| | +--- org.springframework.boot:spring-boot-starter-logging:2.1.4.RELEASE
| | | +--- ch.qos.logback:logback-classic:1.2.3
| | | | +--- ch.qos.logback:logback-core:1.2.3
| | | | \--- org.slf4j:slf4j-api:1.7.25 -> 1.7.31
| | | +--- org.apache.logging.log4j:log4j-to-slf4j:2.11.2
| | | | +--- org.slf4j:slf4j-api:1.7.25 -> 1.7.31
| | | | \--- org.apache.logging.log4j:log4j-api:2.11.2
| | | \--- org.slf4j:jul-to-slf4j:1.7.26
| | | \--- org.slf4j:slf4j-api:1.7.26 -> 1.7.31
| | +--- javax.annotation:javax.annotation-api:1.3.2
| | \--- org.springframework:spring-core:5.1.6.RELEASE -> 5.2.3.RELEASE (*)
+--- org.elasticsearch.client:elasticsearch-rest-high-level-client:7.9.3
| | | | | +--- org.elasticsearch:elasticsearch:7.9.3
| | | | | | +--- org.elasticsearch:elasticsearch-core:7.9.3
| | | | | | +--- org.elasticsearch:elasticsearch-secure-sm:7.9.3
| | | | | | +--- org.elasticsearch:elasticsearch-x-content:7.9.3
| | | | | | | +--- org.elasticsearch:elasticsearch-core:7.9.3
| | | | | | | +--- org.yaml:snakeyaml:1.26
| | | | | | | +--- com.fasterxml.jackson.core:jackson-core:2.10.4 -> 2.12.3
| | | | | | | +--- com.fasterxml.jackson.dataformat:jackson-dataformat-smile:2.10.4 (*)
| | | | | | | +--- com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.10.4 (*)
| | | | | | | \--- com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:2.10.4
| | | | | | +--- org.elasticsearch:elasticsearch-geo:7.9.3
| | | | | | +--- org.apache.lucene:lucene-core:8.6.2
| | | | | | +--- org.apache.lucene:lucene-analyzers-common:8.6.2
| | | | | | +--- org.apache.lucene:lucene-backward-codecs:8.6.2
| | | | | | +--- org.apache.lucene:lucene-grouping:8.6.2
| | | | | | +--- org.apache.lucene:lucene-highlighter:8.6.2
| | | | | | +--- org.apache.lucene:lucene-join:8.6.2
| | | | | | +--- org.apache.lucene:lucene-memory:8.6.2
| | | | | | +--- org.apache.lucene:lucene-misc:8.6.2
| | | | | | +--- org.apache.lucene:lucene-queries:8.6.2
| | | | | | +--- org.apache.lucene:lucene-queryparser:8.6.2
| | | | | | +--- org.apache.lucene:lucene-sandbox:8.6.2
| | | | | | +--- org.apache.lucene:lucene-spatial-extras:8.6.2
| | | | | | +--- org.apache.lucene:lucene-spatial3d:8.6.2
| | | | | | +--- org.apache.lucene:lucene-suggest:8.6.2
| | | | | | +--- org.elasticsearch:elasticsearch-cli:7.9.3
| | | | | | | +--- net.sf.jopt-simple:jopt-simple:5.0.2
| | | | | | | \--- org.elasticsearch:elasticsearch-core:7.9.3
| | | | | | +--- com.carrotsearch:hppc:0.8.1
| | | | | | +--- joda-time:joda-time:2.10.4
| | | | | | +--- com.tdunning:t-digest:3.2
| | | | | | +--- org.hdrhistogram:HdrHistogram:2.1.9
| | | | | | +--- org.apache.logging.log4j:log4j-api:2.11.1 -> 2.11.2
| | | | | | \--- org.elasticsearch:jna:5.5.0orange-night-91387
12/14/2021, 3:41 PMorange-night-91387
12/14/2021, 3:42 PMorange-night-91387
12/14/2021, 3:50 PMbrainy-author-77356
12/14/2021, 4:20 PMorange-night-91387
12/14/2021, 5:16 PMorange-night-91387
12/14/2021, 5:22 PMcrooked-baker-53493
12/14/2021, 9:18 PMconstrains doesn't change the log4j dependency introduced by sprint-boot. As recommended below, using resolutionStrategy gives the expected result.
https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot
configurations.all {
resolutionStrategy.eachDependency { DependencyResolveDetails details ->
if (details.requested.group == 'org.apache.logging.log4j') {
details.useVersion '2.15.0'
}
}
}crooked-baker-53493
12/14/2021, 9:20 PM