Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-67357

log4j dependency has critical vulnerability CVE-2021-44228 in Micro Focus Application Automation Tools Plugin

    • 7.2

      See JENKINS-67353

      Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
      This one is less important but will still be detected by scanners and alert all users.

          [JENKINS-67357] log4j dependency has critical vulnerability CVE-2021-44228 in Micro Focus Application Automation Tools Plugin

          Daniel Beck created issue -
          José María Palma made changes -
          Priority Original: Minor [ 4 ] New: Critical [ 2 ]

          Mark Waite added a comment -

          Requires an updated library that provides the Apache Log4j 2 dependency. Once the updated library pull request is merged and released, then the plugin dependency will need to be updated and released.

          Mark Waite added a comment - Requires an updated library that provides the Apache Log4j 2 dependency. Once the updated library pull request is merged and released, then the plugin dependency will need to be updated and released.
          Zhipeng made changes -
          Assignee Original: Paul-Adrian Tofan [ ptofan ] New: Zhipeng [ zhipengwa ]
          Zhipeng made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Wadeck Follonier made changes -
          Description Original: See JENKINS-67353 New: See JENKINS-67353

          (!) Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
          This one is less important but will still be detected by scanners and alert all users.
          Wadeck Follonier made changes -
          Labels Original: CVE-2021-44228 security New: CVE-2021-44228 CVE-2021-45046 security

          Hilda added a comment -

          Hello,

          A new official version of the plugin will be released soon with the fix for log4j 2.16.

          Hilda added a comment - Hello, A new official version of the plugin will be released soon with the fix for log4j 2.16.

          FTR 7.1.2-beta contains log4j 2.15.

          Wadeck Follonier added a comment - FTR 7.1.2-beta contains log4j 2.15.

          Bill Hopper added a comment - - edited

          Ummm... now 2.17.0 is the recommendation.

          Bill Hopper added a comment - - edited Ummm... now 2.17.0 is the recommendation.

            zhipengwa Zhipeng
            danielbeck Daniel Beck
            Votes:
            3 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved: