Skip to content

Octopus-TeamCity vulnerable to CVE-2025-68161 #185

@saschanm

Description

@saschanm

log4j-core and log4j-api version 2.15.0 is showing up on vulnerability scans.

https://nvd.nist.gov/vuln/detail/CVE-2025-68161

I have updated the plugin locally by replacing log4j with latest v2.x jar files to mitigate.
I have advised TeamCity marketplace and raised issue here.

Please update the versions in published plugin.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions