github highmed/highmed-dsf v0.5.4
0.5.4 - CVE-2021-44228 Fix

latest releases: v0.9.3, v0.9.2, v0.9.1...
2 years ago

General remarks:

  • Updating to version 0.5.4 is highly recommended as it closes CVE-2021-44228.
  • If an update is not possible, the following mitigation should be used: for the two services referred to as "app" (ghcr.io/highmed/fhir:0.5.3 and ghcr.io/highmed/bpe:0.5.3) in the docker-compose.yml files, an environment variable must be set to disable the incorrect function in Log4j2:
    EXTRA_JVM_ARGS: -Dlog4j2.formatMsgNoLookups=true
  • To Update, replace existing DSF docker containers with version 0.5.4. For more information on how to upgrade see the Wiki

Fixes include:

  • Log4j2 allowed remote code execution for versions prior to 2.15.0. See #297

Clients released in the binary assets:

Docker containers for this release can be access via the GitHub Docker registry - ghcr.io:

Issues closed:

Don't miss a new highmed-dsf release

NewReleases is sending notifications on new releases.