Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-69476

log4j dependency has critical vulnerability CVE-2021-45046 in Octopus Deploy plugin

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • octopusdeploy-plugin
    • 3.1.9

      Our enterprise security scanning solution has flagged the Octopus Deploy plugin is using a Log4j version which has critical vulnerability CVE-2021-45046. Log4j needs to be updated to at least v2.16.0. Current version of the plugin, v3.1.8, is using v2.15.0.

      See JENKINS-67353

          [JENKINS-69476] log4j dependency has critical vulnerability CVE-2021-45046 in Octopus Deploy plugin

          Jonathan Whitby created issue -
          Jonathan Whitby made changes -
          Link New: This issue relates to SECURITY-2862 [ SECURITY-2862 ]
          Octopus Deploy made changes -
          Assignee Original: Brian Adriance [ badriance ] New: Octopus Deploy [ octopusdeploy ]
          Octopus Deploy made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Octopus Deploy made changes -
          Status Original: In Progress [ 3 ] New: In Review [ 10005 ]
          Octopus Deploy made changes -
          Released As New: 3.1.9
          Resolution New: Fixed [ 1 ]
          Status Original: In Review [ 10005 ] New: Resolved [ 5 ]

            octopusdeploy Octopus Deploy
            jwhitby Jonathan Whitby
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: