Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/arduino/Arduino.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCristian Maglie <c.maglie@arduino.cc>2021-12-13 11:46:46 +0300
committerCristian Maglie <c.maglie@arduino.cc>2021-12-13 11:48:13 +0300
commit640a956743e69929be529db6ee8fccda41049703 (patch)
tree520f0ef1a2af4997ceb8fb7e6f3d013c9d2c8770
parent8ae1f94553a9e8bb229c32c4a4f6bd068762b53e (diff)
Upgrade log4j to 2.15.0 - CVE-2021-44228
-rw-r--r--arduino-core/lib/log4j-api-2.12.0.jarbin273454 -> 0 bytes
-rw-r--r--arduino-core/lib/log4j-api-2.15.0.jarbin0 -> 301805 bytes
-rw-r--r--arduino-core/lib/log4j-core-2.12.0.jarbin1667269 -> 0 bytes
-rw-r--r--arduino-core/lib/log4j-core-2.15.0.jarbin0 -> 1789769 bytes
-rw-r--r--build/shared/revisions.txt3
5 files changed, 3 insertions, 0 deletions
diff --git a/arduino-core/lib/log4j-api-2.12.0.jar b/arduino-core/lib/log4j-api-2.12.0.jar
deleted file mode 100644
index 93f770d64..000000000
--- a/arduino-core/lib/log4j-api-2.12.0.jar
+++ /dev/null
Binary files differ
diff --git a/arduino-core/lib/log4j-api-2.15.0.jar b/arduino-core/lib/log4j-api-2.15.0.jar
new file mode 100644
index 000000000..77f6b2bef
--- /dev/null
+++ b/arduino-core/lib/log4j-api-2.15.0.jar
Binary files differ
diff --git a/arduino-core/lib/log4j-core-2.12.0.jar b/arduino-core/lib/log4j-core-2.12.0.jar
deleted file mode 100644
index fbab72063..000000000
--- a/arduino-core/lib/log4j-core-2.12.0.jar
+++ /dev/null
Binary files differ
diff --git a/arduino-core/lib/log4j-core-2.15.0.jar b/arduino-core/lib/log4j-core-2.15.0.jar
new file mode 100644
index 000000000..5d6a73a65
--- /dev/null
+++ b/arduino-core/lib/log4j-core-2.15.0.jar
Binary files differ
diff --git a/build/shared/revisions.txt b/build/shared/revisions.txt
index 0598f44fb..85a9160a9 100644
--- a/build/shared/revisions.txt
+++ b/build/shared/revisions.txt
@@ -1,5 +1,8 @@
ARDUINO 1.8.17 Not yet released
+[ide]
+* Upgrade log4j to 2.15.0 - CVE-2021-44228 (thanks @rhowe)
+
ARDUINO 1.8.16 2021.09.06