GHSA-2qrg-x229-3v8qCriticalCVSS 9.8

Deserialization of Untrusted Data in Log4j

Published
January 6, 2020
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17.

Users are advised to migrate to org.apache.logging.log4j:log4j-core.

🎯 Affected products2

  • maven/log4j:log4j:>= 1.2, <= 1.2.17
  • maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17:= 2.0

🔗 References (217)