Re: Maven Dependency Plugin - Log4j vulnerabilities

2022-03-02 Thread Jaladi, Venumadhav
; rely on the maven dependency plugin at runtime? Does it mean you’re >> pulling >> >> maven dependencies after application startup? >> >> >> >> > On Feb 28, 2022, at 03:30, Slawomir Jaranowski < >> s.jaranow...@gmail.com> &g

Re: Maven Dependency Plugin - Log4j vulnerabilities

2022-02-27 Thread Jaladi, Venumadhav
Hi team, Can I expect any response? Is this the right email address for my question? Thanks, Venu On Thu, Feb 24, 2022 at 6:47 AM Jaladi, Venumadhav < jaladi.venumad...@verizon.com> wrote: > Hi team, > > We are using the Maven Dependency Plugin in one of our projects and our &

Maven Dependency Plugin - Log4j vulnerabilities

2022-02-27 Thread Jaladi, Venumadhav
Hi team, We are using the Maven Dependency Plugin in one of our projects and our scanning tools are showing multiple vulnerabilities related to Log4j (CVE-2019-17571, CVE-2020-9488, CVE-2022-23302, CVE-2022-23305, CVE-2022-23307 and CVE-2021-4104). We would like to know if there are any plans to