Dark Mode

Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[fix][sec] Upgrade log4j to 2.25.3 to address CVE-2025-68161#25102

Merged
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-log4j-2.25.3
Dec 22, 2025
Merged

[fix][sec] Upgrade log4j to 2.25.3 to address CVE-2025-68161#25102
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-log4j-2.25.3

Conversation

Copy link
Member

lhotari commented Dec 22, 2025

Motivation

log4j < 2.25.3 contains CVE-2025-68161. It's a vulnerability in the SocketAppender. It doesn't impact Pulsar users with the default configuration since SocketAppender isn't used in the default configuration. However, it's necessary to upgrade library versions to ones that don't contain known vulnerabilities.

Modifications

  • Upgrade log4j2 from 2.25.2 to 2.25.3

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

lhotari added this to the 4.2.0 milestone Dec 22, 2025
lhotari self-assigned this Dec 22, 2025
lhotari requested review from Technoboy-, dao-jun, liangyepianzhou and nodece December 22, 2025 08:41
github-actions bot added the doc-not-needed Your PR changes do not impact docs label Dec 22, 2025
dao-jun approved these changes Dec 22, 2025
nodece approved these changes Dec 22, 2025
Copy link

codecov-commenter commented Dec 22, 2025

Codecov Report

All modified and coverable lines are covered by tests.
Project coverage is 74.45%. Comparing base (3fb52c5) to head (489fc6c).

Additional details and impacted files

@@ Coverage Diff @@
## master #25102 +/- ##
=============================================
+ Coverage 30.84% 74.45% +43.61%
- Complexity 51 33671 +33620
=============================================
Files 1840 1899 +59
Lines 145468 149654 +4186
Branches 16907 17393 +486
=============================================
+ Hits 44863 111429 +66566
+ Misses 93605 29355 -64250
- Partials 7000 8870 +1870
Flag Coverage D
inttests 26.32% (-0.04%)
systests 23.00% (+0.01%)
unittests 73.98% (?)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 1491 files with indirect coverage changes

New features to boost your workflow:
  • Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

lhotari merged commit 4495525 into apache:master Dec 22, 2025
288 of 300 checks passed
lhotari added a commit that referenced this pull request Dec 22, 2025
lhotari added the cherry-picked/branch-4.1 label Dec 22, 2025
lhotari added a commit that referenced this pull request Dec 22, 2025
lhotari added a commit that referenced this pull request Dec 22, 2025
lhotari added the cherry-picked/branch-3.0 label Dec 22, 2025
ganesh-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 28, 2025
manas-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 29, 2025
srinath-ctds pushed a commit to datastax/pulsar that referenced this pull request Dec 29, 2025
lhotari added the cherry-picked/branch-4.0 label Jan 2, 2026
nodece pushed a commit to ascentstream/pulsar that referenced this pull request Jan 5, 2026
manas-ctds pushed a commit to datastax/pulsar that referenced this pull request Jan 19, 2026
Rutuja-IBM pushed a commit to datastax/pulsar that referenced this pull request Feb 9, 2026
Rutuja-IBM pushed a commit to datastax/pulsar that referenced this pull request Feb 9, 2026
Rutuja-IBM pushed a commit to datastax/pulsar that referenced this pull request Feb 12, 2026
Rutuja-IBM pushed a commit to datastax/pulsar that referenced this pull request Feb 13, 2026
manas-ctds pushed a commit to datastax/pulsar that referenced this pull request Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

nodece nodece approved these changes

dao-jun dao-jun approved these changes

Technoboy- Awaiting requested review from Technoboy-

liangyepianzhou Awaiting requested review from liangyepianzhou

Assignees

lhotari

Projects

None yet

Milestone

4.2.0

Development

Successfully merging this pull request may close these issues.

4 participants