Bump log4j version to 2.16.0 per CVE-2021-45046 (#13518) (#13521)

To err on the side of caution it'd be preferable to use log4j 2.16.0 due to CVE-2021-45046

(cherry picked from commit bf0b122b37)

Co-authored-by: thex12 <thex12@users.noreply.github.com>
This commit is contained in:
Ry Biesemeyer 2021-12-15 21:42:16 -08:00 committed by GitHub
parent c3b0bb4224
commit 06361b5161
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -30,7 +30,7 @@ String jrubyVersion = versionMap['jruby']['version']
String jacksonVersion = versionMap['jackson']
String jacksonDatabindVersion = versionMap['jackson-databind']
String log4jVersion = '2.15.0'
String log4jVersion = '2.16.0'
repositories {
mavenCentral()