Vulnerability GHSA-f7vh-qwp3-x37m
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
4 years ago
January 19, 2022 at 12:01 AM UTC
Deserialization of Untrusted Data in Apache Log4j
1.1.3
1.1.3
Summary
Deserialization of Untrusted Data in Apache Log4j
Details
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from log4j:log4j to org.apache.logging.log4j:log4j for an updated version of the library.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 years ago
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
1.1.3 GHSA-vp98-w2p3-mv35
1.1.3 GHSA-vp98-w2p3-mv35
High Risk
4 years ago
Deserialization of Untrusted Data in Log4j 1.x
2.0.0 GHSA-w9p3-5cr8-m3jj
2.0.0 GHSA-w9p3-5cr8-m3jj
High Risk
4 years ago
Deserialization of Untrusted Data in Log4j 1.x
2.0.0 GHSA-w9p3-5cr8-m3jj
2.0.0 GHSA-w9p3-5cr8-m3jj
Critical
4 years ago
SQL Injection in Log4j 1.2.x
2.0.0 GHSA-65fg-84f6-3jq3
2.0.0 GHSA-65fg-84f6-3jq3
Critical
4 years ago
SQL Injection in Log4j 1.2.x
2.0.0 GHSA-65fg-84f6-3jq3
2.0.0 GHSA-65fg-84f6-3jq3
Impacted packages
Timeline
Published
4 years ago
January 19, 2022 at 12:01 AM UTC
Last Modified
2 years ago
November 08, 2023 at 04:08 AM UTC