apache / apache/jmeter

Log4j issue CVE-2025-68161 in Jmeter 5.6.3

Open
#6,653 4 comments 0 reactions 0 assignees View on GitHub
defect to-triage
Dominant language
Java
Stars
9.5k
Forks
2.3k
Avg merge
1d 22h
Merged PRs (30d)
5

Description

### Expected behavior

Hi!
I have noticed that the Log4j version being used in Apache Jmeter 5.6.3 is version 2.22.1
This Log4j version is vulnerable to CVE-2025-68161 (Log4j up to version 2.25.2)
We are using Microsoft Defender in our organization to monitor threats.
I need guidance in how to manage this security issue.
Does Jmeter need to release a new version or can we manually change the Log4j version somehow?
When can we expect a new version of Jmeter?

### Actual behavior

Actual file path: C:\....\apache-jmeter-5.6.3\lib\log4j-core-2.22.1.jar

### Steps to reproduce the problem

-

### JMeter Version

5.6.3

### Java Version

Not relevant

### OS Version

Windows 11

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.