'How to fix log4j vulnerability [closed]

I heard Log4j core is vulnerable according to https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot

So I need a fix to get rid of vulnerabilities from my services!

I am trying to bump up log4j from older versions to 2.15.0

I can manually upgrade the dependencies but the problem is I don't know, is there any dependency that is downloading the log4j older version or not!

So I want some solution that will just upgrade the log4j dependency in my projects either they are direct or transitive :)



Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source