This is an automated email from the ASF dual-hosted git repository. git-site-role pushed a commit to branch asf-site in repository https://gitbox.apache.org/repos/asf/struts-site.git
The following commit(s) were added to refs/heads/asf-site by this push: new 87176f2 Automatic Site Publish by Buildbot 87176f2 is described below commit 87176f25dcf64aeec00d15317b66445c19c65578 Author: buildbot <us...@infra.apache.org> AuthorDate: Thu Dec 23 07:26:22 2021 +0000 Automatic Site Publish by Buildbot --- output/announce-2021.html | 3 +++ 1 file changed, 3 insertions(+) diff --git a/output/announce-2021.html b/output/announce-2021.html index 0a74317..cf7b5c1 100644 --- a/output/announce-2021.html +++ b/output/announce-2021.html @@ -151,6 +151,9 @@ release. The GA designation is our highest quality grade.</p> <p>This release addresses Log4j vulnerability <a href="https://logging.apache.org/log4j/2.x/security.html#CVE-2021-45105">CVE-2021-45105</a> by using the latest Log4j 2.12.3 version (Java 1.7 compatible).</p> +<p><strong>Please note, that the Apache Struts itself depends on the log4j-api package only, it’s users’ responsibility +to use a proper version of the log4j-core package!</strong></p> + <blockquote> <p>Please read the <a href="https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.5.28.2">Version Notes</a> to find more details about performed bug fixes and improvements.</p>