From 640a956743e69929be529db6ee8fccda41049703 Mon Sep 17 00:00:00 2001 From: Cristian Maglie Date: Mon, 13 Dec 2021 09:46:46 +0100 Subject: Upgrade log4j to 2.15.0 - CVE-2021-44228 --- arduino-core/lib/log4j-api-2.12.0.jar | Bin 273454 -> 0 bytes arduino-core/lib/log4j-api-2.15.0.jar | Bin 0 -> 301805 bytes arduino-core/lib/log4j-core-2.12.0.jar | Bin 1667269 -> 0 bytes arduino-core/lib/log4j-core-2.15.0.jar | Bin 0 -> 1789769 bytes build/shared/revisions.txt | 3 +++ 5 files changed, 3 insertions(+) delete mode 100644 arduino-core/lib/log4j-api-2.12.0.jar create mode 100644 arduino-core/lib/log4j-api-2.15.0.jar delete mode 100644 arduino-core/lib/log4j-core-2.12.0.jar create mode 100644 arduino-core/lib/log4j-core-2.15.0.jar diff --git a/arduino-core/lib/log4j-api-2.12.0.jar b/arduino-core/lib/log4j-api-2.12.0.jar deleted file mode 100644 index 93f770d64..000000000 Binary files a/arduino-core/lib/log4j-api-2.12.0.jar and /dev/null differ diff --git a/arduino-core/lib/log4j-api-2.15.0.jar b/arduino-core/lib/log4j-api-2.15.0.jar new file mode 100644 index 000000000..77f6b2bef Binary files /dev/null and b/arduino-core/lib/log4j-api-2.15.0.jar differ diff --git a/arduino-core/lib/log4j-core-2.12.0.jar b/arduino-core/lib/log4j-core-2.12.0.jar deleted file mode 100644 index fbab72063..000000000 Binary files a/arduino-core/lib/log4j-core-2.12.0.jar and /dev/null differ diff --git a/arduino-core/lib/log4j-core-2.15.0.jar b/arduino-core/lib/log4j-core-2.15.0.jar new file mode 100644 index 000000000..5d6a73a65 Binary files /dev/null and b/arduino-core/lib/log4j-core-2.15.0.jar differ diff --git a/build/shared/revisions.txt b/build/shared/revisions.txt index 0598f44fb..85a9160a9 100644 --- a/build/shared/revisions.txt +++ b/build/shared/revisions.txt @@ -1,5 +1,8 @@ ARDUINO 1.8.17 Not yet released +[ide] +* Upgrade log4j to 2.15.0 - CVE-2021-44228 (thanks @rhowe) + ARDUINO 1.8.16 2021.09.06 -- cgit v1.2.3