Highlights
Remote Code Execution: 1 prior fix. Scrutinize any change in this area.
pom.xml: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Remote Code Execution: The project bundled a vulnerable version of Apache Log4j 2 susceptible to the Log4Shell vulnerability (CVE-2021-44228), which permits remote code execution via malicious JNDI lookup strings in log messages. This risk resurfaces whenever bundled log engine dependencies fall out of sync with upstream security patches.