Skip to main content
Question

RunDeck Log4J Vulnerability

  • July 23, 2026
  • 0 replies
  • 5 views

Forum|alt.badge.img

Previously I reported a CVE associated with Log4J Log4jLink.  This was resolved with the release of 6.0.  Thanks!  Almost immediately after I upgraded to 6.0, I got flagged on a new CVE:  

Plugin Name:

  Apache Log4j 2.13.1 < 2.25.5 / 2.26.0 < 2.26.1 Improper JSON Serialization (CVE-2026-49844)

Plugin Output:
  Path              : /var/lib/rundeck/bootstrap/rundeck-6.0.0-20260629.war
  Installed version : 2.25.4
  Fixed version     : 2.25.5

Is there a plan for upgrading the Log4J version again?  Please advise.

 

Thanks,

Eric