Please patch CVEs for package bookkeeper version 4.3.2 INFO (CVEs are): bookkeeper 4.3.2 cves found CVE-2019-17571 Desc: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. Link: https://nvd.nist.gov/vuln/detail/CVE-2019-17571 Severity: CRITICAL
*** This bug has been marked as a duplicate of bug 13824 ***