
12/15/2021 · GitLab
What this post added
Updated SAST and Dependency Scanning analyzers to use Log4j 2.17.1. Removed Log4j as a dependency from the license scanning analyzer. Investigated and determined low impact for CVE-2021-44832. Updated Log4j to version 2.16 in Spotbugs and Gemnasium-Maven analyzers for CVE-2021-45105 and CVE-2021-44228. Provided guidance for customers on updating analyzers and offline environments.