SUSE-SU-2021:4096-1
Dashboard / Vulnerabilities / SUSE-SU-2021:4096-1
SUSE-SU-2021:4096-1
Summary: Security update for storm
Details: This update for storm fixes the following issues: - Remove JndiLookup from log4j 2.x jars during build to prevent 'log4shell' code injection. (bsc#1193641, bsc#1193611, CVE-2021-44228) - Remove JMSAppender from log4j 1.2.x jars during build to prevent attacks when JMS is enabled (bsc#1193641, bsc#1193662, CVE-2021-4104)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20214096-1/, https://bugzilla.suse.com/1193611, https://bugzilla.suse.com/1193641, https://bugzilla.suse.com/1193662, https://www.suse.com/security/cve/CVE-2021-4104, https://www.suse.com/security/cve/CVE-2021-44228
Affected packages
Package
Name: storm
Purl: pkg:rpm/suse/storm&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
