Răsfoiți Sursa

升级log4j2到安全版本,防止漏洞风险

RuoYi 3 ani în urmă
părinte
comite
bb4d75aff0
1 a modificat fișierele cu 14 adăugiri și 0 ștergeri
  1. 14 0
      pom.xml

+ 14 - 0
pom.xml

@@ -33,6 +33,7 @@
         <poi.version>4.1.2</poi.version>
         <velocity.version>2.3</velocity.version>
         <jwt.version>0.9.1</jwt.version>
+        <log4j2.version>2.15.0</log4j2.version>
     </properties>
 	
     <!-- 依赖声明 -->
@@ -150,6 +151,19 @@
                 <version>${fastjson.version}</version>
             </dependency>
 
+            <!-- log4j日志组件 -->
+            <dependency>
+                <groupId>org.apache.logging.log4j</groupId>
+                <artifactId>log4j-api</artifactId>
+                <version>${log4j2.version}</version>
+            </dependency>
+            
+            <dependency>
+                <groupId>org.apache.logging.log4j</groupId>
+                <artifactId>log4j-to-slf4j</artifactId>
+                <version>${log4j2.version}</version>
+            </dependency>
+
             <!-- Token生成与解析-->
             <dependency>
                 <groupId>io.jsonwebtoken</groupId>