Log4j issue CVE-2025-68161 in Jmeter 5.6.3
Open
defect
to-triage
- Dominant language
- Java
- Stars
- 9.5k
- Forks
- 2.3k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 5
Description
### Expected behavior
Hi!
I have noticed that the Log4j version being used in Apache Jmeter 5.6.3 is version 2.22.1
This Log4j version is vulnerable to CVE-2025-68161 (Log4j up to version 2.25.2)
We are using Microsoft Defender in our organization to monitor threats.
I need guidance in how to manage this security issue.
Does Jmeter need to release a new version or can we manually change the Log4j version somehow?
When can we expect a new version of Jmeter?
### Actual behavior
Actual file path: C:\....\apache-jmeter-5.6.3\lib\log4j-core-2.22.1.jar
### Steps to reproduce the problem
-
### JMeter Version
5.6.3
### Java Version
Not relevant
### OS Version
Windows 11
Contributor guide
Assessment
This issue has not been assessed yet.