Forum Discussion

MarkJohnsonekl's avatar
MarkJohnsonekl
New Contributor
3 years ago

Will SoapUI 5.6.1 be modified to download log4j 2.17.0?

It seems to download 2.16.0 now, which is not acceptable to our security team.

  • MarkJohnsonekl's avatar
    MarkJohnsonekl
    3 years ago

    I see form another post that SoapUI OS  5.7.0 is being developed, and will include Log4J 2.17.0.   This issue can be closed

  • richie's avatar
    richie
    Community Hero

    Hey MarkJohnsonekl 

     

     

    v2.16 of the log4j files are the ones that have had that security hole plugged.  Are you saying your security team wont allow v2.16 log4j files?

     

    Cheers,

     

    Rich

    • richie's avatar
      richie
      Community Hero

      ignore my last -I just saw the post by KarelHusa about the latest security hole for v2.16 log4j

    • MarkJohnsonekl's avatar
      MarkJohnsonekl
      New Contributor

      My understanding is that 2.16.0 resolved the critical vulnerability that was introduced by 2.14, but - since then - vulnerabilities were discovered in 2.16.0, and one of these has been classified as critical.  The known vulnerabilities that exist in 2.16.0 are mediated by 2.17.0.      So, our organization only considers 2.17.0 an acceptable remediation.   

      • MarkJohnsonekl's avatar
        MarkJohnsonekl
        New Contributor

        I see form another post that SoapUI OS  5.7.0 is being developed, and will include Log4J 2.17.0.   This issue can be closed