diff --git a/CHANGELOG.md b/CHANGELOG.md index a12fdf048e9eb9e555a7cd18b692abe69f5bf421..2a226e2b68f9c059490ff255a91198b04504998d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -31,9 +31,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 * [caosdb-server#174](https://gitlab.indiscale.com/caosdb/src/caosdb-server/-/issues/174) GRPC-API: Server should gracefully handle non-file entities with file-like attributes. +* [caosdb-server#220](https://gitlab.indiscale.com/caosdb/src/caosdb-server/-/issues/220) + Entities can be retrieved via GRPC despite insufficient permissions. +* [caosdb-server#223](https://gitlab.indiscale.com/caosdb/src/caosdb-server/-/issues/223) + State is being leaked even though RETRIEVE:ENTITY permission is not granted. ### Security +* Update of logging backend log4j to 2.17.2 +* Fix for [caosdb-server#220](https://gitlab.indiscale.com/caosdb/src/caosdb-server/-/issues/220) + Entities can be retrieved via GRPC despite insufficient permissions. +* Fix for [caosdb-server#223](https://gitlab.indiscale.com/caosdb/src/caosdb-server/-/issues/223) + State is being leaked even though RETRIEVE:ENTITY permission is not granted. ## [v0.7.1] - 2021-12-13 (Timm Fitschen) diff --git a/pom.xml b/pom.xml index 1d665fcea44e070f38afb1cc17da3086916cc108..733a5b4ca3c741fef0d611885327545eee8c0129 100644 --- a/pom.xml +++ b/pom.xml @@ -38,7 +38,7 @@ <grpc.version>1.42.1</grpc.version> <netty-tcnative.version>2.0.34.Final</netty-tcnative.version> <restlet.version>2.4.3</restlet.version> - <log4j.version>2.15.0</log4j.version> + <log4j.version>2.17.2</log4j.version> </properties> <repositories> <repository>