3 ms·
Not really? Your link shows that the log4j is not used in core Jenkins. Moreover, they provided a nice test to see, on a particular installation, if any plugin
by cure 5y ago
Not really? Your link shows that the log4j is not used in core Jenkins.
Moreover, they provided a nice test to see, on a particular installation, if any plugins are affected. Judging by the provided link to their issue tracker (https://issues.jenkins.io/browse/JENKINS-67361?jql=labels%20%3D%20CVE-2021-44228 https://issues.jenkins.io/browse/JENKINS-67361?jql=labels%20...), there only seem to be a handful of plugins affected, and none appear to be super widely used.
They are responding really well to this, by the way. That blog post is clear and useful information is being added. Kudos to the Jenkins team!