QID 980407

QID 980407: Java (maven) Security Update for log4j:log4j (GHSA-2qrg-x229-3v8q)

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Users are advised to migrate to `org.apache.logging.log4j:log4j-core`

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-2qrg-x229-3v8q for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980407

    Software Advisories
    Advisory ID Software Component Link
    GHSA-2qrg-x229-3v8q log4j:log4j URL Logo github.com/advisories/GHSA-2qrg-x229-3v8q