Highlights
Remote Code Execution: 1 prior fix. Scrutinize any change in this area.
aws-lambda-java-log4j2/pom.xml: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Remote Code Execution: The project was vulnerable to Remote Code Execution via downstream transitively-used logging libraries. Specifically, utilizing vulnerable versions of Log4j 2 allowed attackers to trigger JNDI lookups, which could lead to arbitrary code execution (Log4Shell variant CVE-2021-45046).