log4j:log4j
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting log4j:log4jpage 1 of 1
- CVE-2019-17571CRITICALCVSS 9.8EG 9.82019-12-20
vulnerable: 1.2.11 ... 1.2.9 (13 versions)
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network…
- CVE-2021-4104HIGHCVSS 7.5EG 7.52021-12-14
vulnerable: 1.2.11 ... 1.2.9 (13 versions)
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causi…
- CVE-2022-23302HIGHCVSS 8.8EG 8.82022-01-18
vulnerable: 1.1.3 ... 1.2.9 (14 versions)
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attack…
- CVE-2022-23305CRITICALCVSS 9.8EG 9.82022-01-18
vulnerable: 1.1.3 ... 1.2.9 (14 versions)
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows att…
- CVE-2022-23307HIGHCVSS 8.8EG 9.82022-01-18
vulnerable: 1.1.3 ... 1.2.9 (14 versions)
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
- CVE-2023-26464HIGHCVSS 7.5EG 7.5✓ Fixed in 2.02023-03-10
vulnerable: 1.1.3 ... 1.2.9 (14 versions)
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hash…
Check whether log4j:log4j is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for log4j:log4j CVEs against the assets you own.
Start Free Scan →