Log4j remindiation - CVE-2025-68161

How would I remediate log4j that keep coming up on the security scan CVE-2025-68161. The suggested solution is Upgrade to Apache Log4j version 2.25.3 or later.

OS: UNIX
Java Version: Java 17
Tomcat Version: 11
Lucee Version: 6.2.2.91

What’s the first rule of CVE club?

Read the CVE!

Here’s a good breakdown

Lucee unless manually configured does not use the Socket Appender, as such Lucee is not vulnerable to this CVE

Even if you did, it requires your (hopefully) internal network to be compromised, which is a far larger problem than this CVE

We will in due course update the library

1 Like

can I update the core files to use 2.25.3

Thanks for the reminder. Here’s the official status.

With Lucee’s default logging setup this isn’t exploitable. CVE-2025-68161 and the related Log4j CVEs from this year (CVE-2026-34477 and others) only affect specific appenders or layouts, like the Socket/SMTP/Syslog appenders with TLS, Log4j’s XmlLayout, Rfc5424Layout or JsonTemplateLayout. Lucee uses its own appenders and layouts unless you configure one of those yourself.

We’ll still update Log4j so scanners are happy, in 6.2, 7.0, 7.1 and 8.0. That’s tracked in LDEV-6518.

Please don’t replace the Log4j jars in the core yourself. Lucee loads Log4j as its own OSGi bundles (org.lucee:log4j-core / log4j-api), so the plain Apache jars won’t be picked up. Watch the ticket instead; we’ll post here once there’s a build to test.