Package
sonarqube
Component
log4j-core
Latest update
Fixed version
26.7.0.124771-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
26.7.0.124771-r0Status
Status
Impact
Log4j-core vulnerabilities exist in bundled Elasticsearch JARs: elasticsearch-log4j-8.19.10.jar (contains log4j-core 2.19.0). This pre-built JAR cannot be updated through dependency management. Requires upstream SonarQube to upgrade Elasticsearch with the patched log4j version.
Status