CRITICAL 9.8 Maven

Deserialization of Untrusted Data in Log4j

GHSA-fxph-q3j8-mv87 · CVE-2017-5645

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes