Skip to content

Backport HHH-20334 to branch 7.3 - Upgrade to Log4j 2.25.4#12164

Merged
yrodiere merged 2 commits intohibernate:7.3from
yrodiere:HHH-20334-7.3
Apr 13, 2026
Merged

Backport HHH-20334 to branch 7.3 - Upgrade to Log4j 2.25.4#12164
yrodiere merged 2 commits intohibernate:7.3from
yrodiere:HHH-20334-7.3

Conversation

@yrodiere
Copy link
Copy Markdown
Member

@yrodiere yrodiere commented Apr 13, 2026

https://hibernate.atlassian.net/browse/HHH-20334

Backport of #12163


Please make sure that the following tasks are completed:
Tasks specific to HHH-20334 (Task):

  • Add test OR check there is no need for a test
  • Update documentation as relevant: javadoc for changed API, documentation/src/main/asciidoc/userguide for all features, documentation/src/main/asciidoc/introduction for main features, links from existing documentation
  • Add entries as relevant to migration-guide.adoc (breaking changes) and whats-new.adoc (new features/improvements)

Log4j 2.25 is more strict with its checks.

Fix extracted from hibernate@6c3c168
Technically we only:

1. Use it for testing
2. Have an API dependency in hibernate-testing, which provides some tools to work with log4j

So the various CVEs are not really relevant:

* https://logging.apache.org/security.html#CVE-2026-34478
* https://logging.apache.org/security.html#CVE-2026-34479
* https://logging.apache.org/security.html#CVE-2026-34481

Still, let’s avoid the noise related to automated tools reporting the problem.
@sonarqubecloud
Copy link
Copy Markdown

@yrodiere
Copy link
Copy Markdown
Member Author

The Jenkins failure is unrelated; it's a known flake in Maven Plugin tests: https://hibernate.zulipchat.com/#narrow/channel/132094-hibernate-orm-dev/topic/EnhancerMojoIT.20failing/with/585151353
TCK failures are pre-existing

@yrodiere yrodiere merged commit 0c4f489 into hibernate:7.3 Apr 13, 2026
26 of 29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants