GHSA-94g7-hpv8-h9qm: Remote code injection in Log4j
(updated )
Logging untrusted or user controlled data with a vulnerable version of Log4J may result in Remote Code Execution (RCE) against your application. This includes untrusted data included in logged errors such as exception traces, authentication failures, and other unexpected vectors of user controlled input.
More Details: https://github.com/advisories/GHSA-jfh8-c2jp-5v3q
References
Code Behaviors & Features
Detect and mitigate GHSA-94g7-hpv8-h9qm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →