1.9.1
Ray-1.9.1
Security 1
- Bump log4j2 version from 2.14 to 2.16 to resolve CVE-2021-44228 and CVE-2021-45046
Patch release to bump the log4j2 version from 2.14 to 2.16. This resolves the security vulnerabilities https://nvd.nist.gov/vuln/detail/CVE-2021-44228 and https://nvd.nist.gov/vuln/detail/CVE-2021-45046.
No library or core changes included.
Thanks @seonggwonyoon and @ijrsvt for contributing the fixes!