Skip to main content
Solved

RunDeck Log4J Vulnerability

  • July 23, 2026
  • 4 replies
  • 127 views

Forum|alt.badge.img

Previously I reported a CVE associated with Log4J Log4jLink.  This was resolved with the release of 6.0.  Thanks!  Almost immediately after I upgraded to 6.0, I got flagged on a new CVE:  

Plugin Name:

  Apache Log4j 2.13.1 < 2.25.5 / 2.26.0 < 2.26.1 Improper JSON Serialization (CVE-2026-49844)

Plugin Output:
  Path              : /var/lib/rundeck/bootstrap/rundeck-6.0.0-20260629.war
  Installed version : 2.25.4
  Fixed version     : 2.25.5

Is there a plan for upgrading the Log4J version again?  Please advise.

 

Thanks,

Eric

Best answer by MegaDrive68k

Hi Eric, we updated the affected library in the upcoming 6.1 release (currently in RC2), so the CVE will be resolved in that version. Thanks!

4 replies

Forum|alt.badge.img
  • Author
  • Contributor ✍️
  • July 28, 2026

I hacked the log4j in the 6.0 war file.  It was somewhat painful but will be ok until this is available.


Forum|alt.badge.img
  • PagerDuty Team 📟
  • July 29, 2026

Thanks for your report Eric! I’m reporting this to the engineering team.


Forum|alt.badge.img
  • PagerDuty Team 📟
  • Answer
  • July 29, 2026

Hi Eric, we updated the affected library in the upcoming 6.1 release (currently in RC2), so the CVE will be resolved in that version. Thanks!


Forum|alt.badge.img
  • Author
  • Contributor ✍️
  • July 29, 2026

Thanks so much!  Will be nice to get back to “official release”.  I hate having to hack war files, especially with spring boot’s latest versions…  Hopefully log4j won’t be infiltrated right away again.