{"id":"GHSA-j7c3-96rf-jrrp","aliases":[],"url":"https://o3.security/vulnerability/GHSA-j7c3-96rf-jrrp","summary":"Critical vulnerability in log4j may affect generated PEAR projects","details":"### Impact\nUIMA PEAR projects that have been generated with the `de.averbis.textanalysis:pear-archetype ` version `2.0.0` have a maven dependency with scope `test` to` log4j 2.8.2` and might be affected by CVE-2021-44228.\n\n### Patches\n- The issue has been resolved in `de.averbis.textanalysis:pear-archetype ` version `2.0.1`. Please make sure to use `de.averbis.textanalysis:pear-archetype ` version >= `2.0.1` for generating new PEAR projects.\n\n- Existing maven PEAR projects can be patched by manually upgrading to `log4j` >= `2.16.0` in `pom.xml`.\n\n\n### References\nhttps://www.lunasec.io/docs/blog/log4j-zero-day/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/averbis/pear-archetype/issues\n","published":"2021-12-16T21:01:51Z","modified":"2021-12-16T18:57:47Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"de.averbis.textanalysis:pear-archetype","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/averbis/pear-archetype/commit/6815f5981c836ab8c345a6ff54f29e9f4b67f7eb","label":"averbis/pear-archetype@6815f59"},"references":[{"type":"WEB","url":"https://github.com/averbis/pear-archetype/security/advisories/GHSA-j7c3-96rf-jrrp"},{"type":"WEB","url":"https://github.com/averbis/pear-archetype/commit/6815f5981c836ab8c345a6ff54f29e9f4b67f7eb"},{"type":"PACKAGE","url":"https://github.com/averbis/pear-archetype"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-12-16T18:57:47Z"}}