diff --git a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html index dec1372be0..9000873455 100644 --- a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html +++ b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html @@ -32,6 +32,7 @@
WARNING: There has been a published CVE security vulnerability noted in Ghidra dependencies within two log4j jar files. + We strongly encourage anyone using previous versions of Ghidra or a build from source, to remediate this issue by either upgrading + to the latest Ghidra 10.1 version, or patching your current version.
+ ++ To patch your current Ghidra installation, delete: +
+ + ++
- Ghidra/Framework/Generic/lib/log4j-api-2.12.1.jar
+- Ghidra/Framework/Generic/lib/log4j-core-2.12.1.jar
+
+ and replace with the newer log4j 2.15.0 version: +
+ + ++
- log4j-api-2.15.0.jar
+- log4j-core-2.15.0.jar
+
+ You can find these in the latest Ghidra 10.1 release, or from: +
+ + ++
- https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-api/2.15.0/log4j-api-2.15.0.jar
+- https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.15.0/log4j-core-2.15.0.jar
+
+ The details of the vulnerability can be found here: +
+ ++
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
+
Ghidra 10.1 is fully backward compatible with project data from previous releases. However, programs and data type archives which are created or modified in 10.1 will not be useable by an earlier Ghidra version.