Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

Deserialization of Untrusted Data in Log4j

GHSA-2qrg-x229-3v8q · CVE-2019-17571

Published · Modified

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17.

Users are advised to migrate to org.apache.logging.log4j:log4j-core.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes