A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.
Summary
| CVE | CVE-2022-23307 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-18 16:15:08 UTC |
| Updated | 2024-11-21 06:48:22 UTC |
| Description | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.026030000 probability, percentile 0.858450000 (date 2026-05-28)
Problem Types: CWE-502 | CWE-502 CWE-502 Deserialization of Untrusted Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Log4j 1.x | affected 1.2.1 unspecified custom | Not specified |
| CNA | Apache Software Foundation | Apache Log4j 1.x | affected unspecified 2.0-alpha1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Apache log4j 1.2 - | af854a3a-2127-422b-91ae-364da2661108 | logging.apache.org | Vendor Advisory |
| lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: @kingkk (en)
Additional Advisory Data
Workarounds
CNA: Upgrade to Apache Log4j 2 and Apache Chainsaw 2.1.0.
Legacy QID Mappings
- 159603 Oracle Enterprise Linux Security Update for parfait:0.5 (ELSA-2022-0290)
- 159628 Oracle Enterprise Linux Security Update for log4j (ELSA-2022-0442)
- 159853 Oracle Enterprise Linux Security Update for log4j (ELSA-2022-9419)
- 179047 Debian Security Update for apache-log4j1.2 (DLA 2905-1)
- 179210 Debian Security Update for apache-log4j1.2 (CVE-2022-23307)
- 199275 Ubuntu Security Notification for Apache Log4j Vulnerabilities (USN-5998-1)
- 240034 Red Hat Update for parfait:0.5 (RHSA-2022:0289)
- 240035 Red Hat Update for parfait:0.5 (RHSA-2022:0290)
- 240036 Red Hat Update for parfait:0.5 (RHSA-2022:0291)
- 240059 Red Hat Update for JBoss Enterprise Application Platform 7.4 (RHSA-2022:0436)
- 240060 Red Hat Update for JBoss Enterprise Application Platform 6.4 (RHSA-2022:0438)
- 240062 Red Hat Update for rh-maven36-log4j12 (RHSA-2022:0439)
- 240067 Red Hat Update for log4j (RHSA-2022:0442)
- 240078 Red Hat Update for red hat jboss web server 3.1 service pack 14 (RHSA-2022:0524)
- 240209 Red Hat Update for JBoss Enterprise Application Platform 7.4.4 (RHSA-2022:1296)
- 240210 Red Hat Update for JBoss Enterprise Application Platform 7.4.4 (RHSA-2022:1297)
- 240452 Red Hat Update for parfait:0.5 (RHSA-2022:0294)
- 240508 Red Hat Update for JBoss Enterprise Application Platform 6.4.2 (RHSA-2022:5459)
- 240511 Red Hat Update for JBoss Enterprise Application Platform 6.4.2 (RHSA-2022:5460)
- 257151 CentOS Security Update for log4j (CESA-2022:0442)
- 353173 Amazon Linux Security Advisory for log4j : ALAS2-2022-1750
- 354858 Amazon Linux Security Advisory for log4j : ALAS-2023-1718
- 355080 Amazon Linux Security Advisory for log4j : AL2012-2023-404
- 376438 IBM WebSphere Application Server Arbitrary Code Execution Vulnerability (Log4Shell) (6557248)
- 376504 Apache Chainsaw Malicious Code Execution Vulnerability
- 376639 IBM Integration Bus and IBM App Connect Enterprise Apache Log4j Vulnerabilities (6568731)
- 377086 Alibaba Cloud Linux Security Update for log4j (ALINUX2-SA-2022:0010)
- 377147 Alibaba Cloud Linux Security Update for parfait:0.5 (ALINUX3-SA-2022:0006)
- 671400 EulerOS Security Update for log4j (EulerOS-SA-2022-1330)
- 671679 EulerOS Security Update for log4j (EulerOS-SA-2022-1744)
- 730542 Atlassian Confluence Server and Confluence Data Center Log4j Multiple Vulnerabilities (CONFSERVER-78991)
- 730566 Atlassian Jira Server and Data Center Log4j Vulnerability (JRASERVER-73885)
- 731338 Atlassian Bamboo Server and Data Center Multiple Security Vulnerabilities (BAM-21696, BAM-21697)
- 751667 SUSE Enterprise Linux Security Update for log4j (SUSE-SU-2022:0212-1)
- 751669 SUSE Enterprise Linux Security Update for log4j (SUSE-SU-2022:0214-1)
- 751670 OpenSUSE Security Update for log4j (openSUSE-SU-2022:0214-1)
- 751672 SUSE Enterprise Linux Security Update for log4j12 (SUSE-SU-2022:0226-1)
- 751673 OpenSUSE Security Update for log4j12 (openSUSE-SU-2022:0226-1)
- 753187 SUSE Enterprise Linux Security Update for log4j (SUSE-SU-2022:14881-1)
- 940440 AlmaLinux Security Update for parfait:0.5 (ALSA-2022:0290)
- 960689 Rocky Linux Security Update for parfait:0.5 (RLSA-2022:0290)