Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-67356

log4j dependency has critical vulnerability CVE-2021-44228 in Checkmarx Plugin

    • 2021.4.3

      See JENKINS-67353

      Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
      This one is less important but will still be detected by scanners and alert all users.

          [JENKINS-67356] log4j dependency has critical vulnerability CVE-2021-44228 in Checkmarx Plugin

          Daniel Beck created issue -
          Daniel Beck made changes -
          Priority Original: Minor [ 4 ] New: Critical [ 2 ]
          Mark Waite made changes -
          Remote Link New: This issue links to "PR 83 with proposed dependency update to Apache Log4j 2 2.15.0 (Web Link)" [ 27287 ]
          Wadeck Follonier made changes -
          Description Original: See JENKINS-67353 New: See JENKINS-67353

          (!) Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
          This one is less important but will still be detected by scanners and alert all users.
          Mark Waite made changes -
          Remote Link New: This issue links to "PR-81 updates to Apache Log4j 2 release 2.16.0 (Web Link)" [ 27294 ]
          Mark Waite made changes -
          Remote Link Original: This issue links to "PR 83 with proposed dependency update to Apache Log4j 2 2.15.0 (Web Link)" [ 27287 ]
          Mark Waite made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Fixed but Unreleased [ 10203 ]
          Daniel Beck made changes -
          Released As New: 2021.4.3
          Daniel Beck made changes -
          Status Original: Fixed but Unreleased [ 10203 ] New: Closed [ 6 ]
          Jenkins CERT Bot made changes -
          Labels Original: CVE-2021-44228 security New: CVE-2021-44228 jcabot:001 jcabot:002 security

            sergeyk Sergey Kadaner
            danielbeck Daniel Beck
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: