org.zenframework.z8.dependencies.commons:log4j-1.2.17
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.zenframework.z8.dependencies.commons:log4j-1.2.17page 1 of 1
- CVE-2019-17571CRITICALCVSS 9.8EG 9.82019-12-20
vulnerable: 2.0
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network…
- CVE-2021-4104HIGHCVSS 7.5EG 7.52021-12-14
vulnerable: 2.0
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causi…
- CVE-2022-23302HIGHCVSS 8.8EG 8.82022-01-18
vulnerable: 2.0
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attack…
- CVE-2022-23305CRITICALCVSS 9.8EG 9.82022-01-18
vulnerable: 2.0
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows att…
- CVE-2022-23307HIGHCVSS 8.8EG 9.82022-01-18
vulnerable: 2.0
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Check whether org.zenframework.z8.dependencies.commons:log4j-1.2.17 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.zenframework.z8.dependencies.commons:log4j-1.2.17 CVEs against the assets you own.
Start Free Scan →