how to upgrade crowd-integration-client regarding CVE-2021-44228

servicedesk
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 14, 2021

All Crowd versions later than 2.6.7 seem to haven an crowd-integration-client-X.X.X.jar that is empty (without classes). Versions up to 2.6.7 make use of log4j version 1.x. 

How do I integrate Crowd in a java application using log4j2? 

The preferred version is crowd-integration-client-3.7.1.jar as we are now using version 3.7.1, but if necessary because of support we can upgrade crowd with a later version.

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events