Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-69476

log4j dependency has critical vulnerability CVE-2021-45046 in Octopus Deploy plugin

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • octopusdeploy-plugin
    • 3.1.9

      Our enterprise security scanning solution has flagged the Octopus Deploy plugin is using a Log4j version which has critical vulnerability CVE-2021-45046. Log4j needs to be updated to at least v2.16.0. Current version of the plugin, v3.1.8, is using v2.15.0.

      See JENKINS-67353

            octopusdeploy Octopus Deploy
            jwhitby Jonathan Whitby
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: