8000 dataflow: update imports and upgrade log4j version by anguillanneuf · Pull Request #6588 · GoogleCloudPlatform/java-docs-samples · GitHub
[go: up one dir, main page]

Skip to content

dataflow: update imports and upgrade log4j version #6588

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Dec 14, 2021
Merged

Conversation

anguillanneuf
Copy link
Member
@anguillanneuf anguillanneuf commented Dec 14, 2021

Another patch to #6587

@product-auto-label product-auto-label bot added api: dataflow Issues related to the Dataflow API. samples Issues that are directly related to samples. labels Dec 14, 2021
Copy link
Contributor
@davidcavazos davidcavazos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thank you!

@anguillanneuf anguillanneuf merged commit 9f782f6 into main Dec 14, 2021
@anguillanneuf anguillanneuf deleted the beam-imports branch December 14, 2021 18:39
gcf-merge-on-green bot pushed a commit that referenced this pull request Dec 20, 2021
Related to #6588 and #6587 
### Background:
As recently reported on [apache.org](https://logging.apache.org/log4j/2.x/security.html)

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DOS (Denial of Service) attack.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: dataflow Issues related to the Dataflow API. samples Issues that are directly related to samples.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
0