5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.ops4j.pax.logging:pax-logging-log4j2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.6
CVE-2021-44832
Improper Input Validation and Injection in Apache Log4j2
HIGH 8.6
CVE-2021-45105
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
CRITICAL 9.0
CVE-2021-45046
Incomplete fix for Apache Log4j vulnerability
CRITICAL 10.0
CVE-2021-44228
Remote code injection in Log4j
UNKNOWN
GHSA-xxfh-x98p-j8fr
Remote code injection in Log4j (through pax-logging-log4j2)
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes