https://bz.apache.org/bugzilla/show_bug.cgi?id=65748
Bug ID: 65748
Summary: jmeter ships with a vulnerable version of log4j2
Product: JMeter
Version: unspecified
Hardware: All
OS: All
Status: NEW
Severity: critical
Priority: P2
Component: Main
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: JMETER_5.5
jmeter 5.4.1 ships with log4j2 in version 2.13.3 which is vulnerable to the
Apache Log4j CVE-2021-44228 vulnerability. Older versions also ship with
affected versions of log4j2.
The log4j2 library should be updated to 2.15.0 containing a fix.
--
You are receiving this mail because:
You are the assignee for the bug.