https://bz.apache.org/bugzilla/show_bug.cgi?id=65748

            Bug ID: 65748
           Summary: jmeter ships with a vulnerable version of log4j2
           Product: JMeter
           Version: unspecified
          Hardware: All
                OS: All
            Status: NEW
          Severity: critical
          Priority: P2
         Component: Main
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: JMETER_5.5

jmeter 5.4.1 ships with log4j2 in version 2.13.3 which is vulnerable to the
Apache Log4j CVE-2021-44228 vulnerability. Older versions also ship with
affected versions of log4j2.
The log4j2 library should be updated to 2.15.0 containing a fix.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to