Forum Discussion

oneagh's avatar
oneagh
New Contributor
1 month ago

Log4j vulnerability (CVE-2025-68161)

Hi everyone,

I’ve tested the latest version of SoapUI (v5.9.1) and noticed that it is still using Log4j v2.17.1

Could you please confirm whether there are plans to upgrade the Log4j component to a newer version, and if so, whether an estimated timeline is available?

Thank you!

2 Replies

  • Hi Oneagh, 

    I raised this with the team and we will be addressing the in the next SoapUI release 5.10.0

    Appreciate you raising this, we can't provide a timeline, but rest assured it will be included

    Cheers,

    Yousaf

    • Securebear532's avatar
      Securebear532
      New Member

      Hi Yousaf!
      What mitigation would you recommend for version 5.9.1 regarding this issue?