Uploaded image for project: 'JS - JS7 JobScheduler Engine'
  1. JS - JS7 JobScheduler Engine
  2. JS-2241

Upgrade log4j-core to version 2.25.3 due to 3rd-party vulnerability CVE-2025-68161

    XMLWordPrintable

Details

    • Fix
    • Status: Dismissed (View Workflow)
    • Medium
    • Resolution: Won't Fix
    • 2.0.0
    • 2.7.8, 2.8.3, 2.9.0
    • None
    • None
    • CVE-2025-68161

    Description

      Current Situation

      • JS7 JOC Cockpit ships with Log4j version 2.24.3 which is affected by the CVE-2025-68161 vulnerability, for details see https://nvd.nist.gov/vuln/detail/CVE-2025-68161.
      • We rate the impact on JS7 products as Low, because JS7 does not make use of the SocketAppender (with TLS over TCP) in question. To exploit the vulnerability, users must individually add this log appender using TLS connections that would not verify hostnames during key exchange when establishing connections.

      Desired Behavior

      Maintainer Notes

      • It is not an option for JS7 products using Log4j 2.25.3 that includes an unacceptable bug. Therefore, the issue is dismissed and will be resumed at a point in time when a working version of Log4j becomes available, probably in Sep 2026.
      • For mitigation of the CVE, users should verify from their log4j2.xml configuration files in use for JOC Cockpit, Controller and Agents, if they individually added a SocketAppender using a TLS connection to an untrusted host.  By default no such log appender is used. For details see JS7 - Log Files and Locations.

      Attachments

        Issue Links

          Activity

            People

              jz Joacim Zschimmer
              sp Santiago Aucejo Petzoldt
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: