Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

Deserialization of Untrusted Data in Log4j

GHSA-fxph-q3j8-mv87 · CVE-2017-5645

Published · Modified

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes