v4.2.8
MateCloud 4.2.8主要为修复log4j2的漏洞而发行的版本。
升级log4j2思路
打开mate-core/mate-starter-dependencies/pom.xml,指定依赖版本
之间增加:
<log4j2.version>2.16.0</log4j2.version>
之间增加
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-api</artifactId>
<version>${log4j2.version}</version>
</dependency>
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-to-slf4j</artifactId>
<version>${log4j2.version}</version>
</dependency>
排除Log4j2的思路
这个思路主要是针对spring-boot-starter-logging这个工具类里排除掉log4j2
之间增加
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-logging</artifactId>
<version>${spring.boot.version}</version>
<exclusions>
<exclusion>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-api</artifactId>
</exclusion>
<exclusion>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-to-slf4j</artifactId>
</exclusion>
</exclusions>
</dependency>