6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether log4j:log4j is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.8
CVE-2019-17571
Deserialization of Untrusted Data in Log4j
CRITICAL 9.8
CVE-2022-23305
SQL Injection in Log4j 1.2.x
HIGH 7.5
CVE-2023-26464
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
HIGH 8.8
CVE-2022-23302
Deserialization of Untrusted Data in Log4j 1.x
CRITICAL 9.8
CVE-2022-23307
Deserialization of Untrusted Data in Apache Log4j
HIGH 7.5
CVE-2021-4104
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes