# How to resolve log4j vulnerabilities

**URL:** https://community.jenkins.io/t/how-to-resolve-log4j-vulnerabilities/1303
**Category:** Ask a question
**Created:** [January 21, 2022, 3:47pm UTC](https://community.jenkins.io/t/how-to-resolve-log4j-vulnerabilities/1303 "2022-01-21T15:47:20Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)
#### Post date: [January 21, 2022, 11:56pm UTC](https://community.jenkins.io/t/how-to-resolve-log4j-vulnerabilities/1303/2 "2022-01-21T23:56:26Z")

</div>

Jenkins doesn’t us log4j. Almost all plugins don’t use log4j and those that did were updated.

How to remedy the non existent situation? Update your core and plugins and file bugs if any remaining plugins still use it.

Also read [https://community.jenkins.io/t/apache-log4j-2-vulnerability-cve-2021-44228](https://community.jenkins.io/t/apache-log4j-2-vulnerability-cve-2021-44228) and the comments

---

_[View the full topic](https://community.jenkins.io/t/how-to-resolve-log4j-vulnerabilities/1303)._
