Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-67358

log4j dependency has critical vulnerability CVE-2021-44228 in lambdatest-automation plugin

    • 1.20.0

      See JENKINS-67353

      Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
      This one is less important but will still be detected by scanners and alert all users.

          [JENKINS-67358] log4j dependency has critical vulnerability CVE-2021-44228 in lambdatest-automation plugin

          Daniel Beck created issue -
          Daniel Beck made changes -
          Priority Original: Minor [ 4 ] New: Critical [ 2 ]
          Wadeck Follonier made changes -
          Description Original: See JENKINS-67353 New: See JENKINS-67353

          (!) Update to 2.15 is not sufficient due to https://nvd.nist.gov/vuln/detail/CVE-2021-45046, it requires 2.16.
          This one is less important but will still be detected by scanners and alert all users.
          Wadeck Follonier made changes -
          Labels Original: CVE-2021-44228 security New: CVE-2021-44228 CVE-2021-45046 security
          Wadeck Follonier made changes -
          Released As New: 1.20.0
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Closed [ 6 ]
          Wadeck Follonier made changes -
          Attachment New: Screenshot_2021-12-17_092159_001.png [ 56959 ]
          Jenkins CERT Bot made changes -
          Labels Original: CVE-2021-44228 CVE-2021-45046 security New: CVE-2021-44228 CVE-2021-45046 jcabot:001 jcabot:002 security

            lambdatest LambdaTest Automation
            danielbeck Daniel Beck
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: