Skip to content

[FP]: log4j-api is not log4j core #8228

@vmj

Description

@vmj

Package URl

pkg:maven/org.apache.logging.log4j/[email protected]

CPE

cpe:2.3:a:apache:log4j:2.24.3:::::::*

CVE

CVE-2025-68161

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

12.2.0

Description

As far as I can tell, the vulnerability is in log4j core. Shipping log4j-api does not imply that core is included, too.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions