tree 59b0236af780a16059ed7f50ad6e0d2a16e4bd1d
parent 519e50faeded50d9f5bdda99627bdafe765f9480
author Alexey Serbin <alexey@apache.org> 1639166372 -0800
committer Alexey Serbin <aserbin@cloudera.com> 1639508677 +0000

[java] bump log4j up to 2.15.0 version

Kudu doesn't use Java for the server-side components, but to keep
various security scanners happy regarding the recent security
vulnerabilities like [1], let's update the log4j package up to the
recently released 2.15.0 version (2021-12-06).  Release notes for the
new version of the package is available at [2].

[1] https://logging.apache.org/log4j/2.x/security.html
[2] https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0

Change-Id: Ib7317447f24916795d8f00e3f6c418707c7fd4ff
Reviewed-on: http://gerrit.cloudera.org:8080/18084
Reviewed-by: Andrew Wong <awong@cloudera.com>
Reviewed-by: Greg Solovyev <gsolovyev@cloudera.com>
Tested-by: Kudu Jenkins
(cherry picked from commit 44e517519e1507eafe58bd9179940160e6934079)
  Conflicts:
    java/gradle/dependencies.gradle
Reviewed-on: http://gerrit.cloudera.org:8080/18089
Reviewed-by: Alexey Serbin <aserbin@cloudera.com>
Reviewed-by: Bankim Bhavsar <bankim@cloudera.com>
Tested-by: Alexey Serbin <aserbin@cloudera.com>
