Insecure deserialization In log4j:log4j
Description
Deserialization of Untrusted Data in Log4j Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17.
Users are advised to migrate to org.apache.logging.log4j:log4j-core.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | >=1.2 <=1.2.17 | - | |
debian 13 | >=0 <1.2.17-9 | 1.2.17-9 | |
debian 14 | >=0 <1.2.17-9 | 1.2.17-9 | |
maven | =2.0 | - | |
debian 11 | >=0 <1.2.17-9 | 1.2.17-9 | |
debian 12 | >=0 <1.2.17-9 | 1.2.17-9 | |
maven | >=1.2 <=1.2.17 | 2.0-alpha1 | |
rpm rhel7 | <0:1.2.17-16.el7_4 | 0:1.2.17-16.el7_4 | |
rpm rhel5 | - | - | |
rpm rhel6 | - | - |
Aliases
References
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.