Previously I reported a CVE associated with Log4J Log4jLink. This was resolved with the release of 6.0. Thanks! Almost immediately after I upgraded to 6.0, I got flagged on a new CVE:
Plugin Name:
Apache Log4j 2.13.1 < 2.25.5 / 2.26.0 < 2.26.1 Improper JSON Serialization (CVE-2026-49844)
Plugin Output:
Path : /var/lib/rundeck/bootstrap/rundeck-6.0.0-20260629.war
Installed version : 2.25.4
Fixed version : 2.25.5
Is there a plan for upgrading the Log4J version again? Please advise.
Thanks,
Eric