CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-23307 CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a c... 8.8 - HIGH 2022-01-18 2022-07-25
CVE-2022-23305 By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inser... 9.8 - CRITICAL 2022-01-18 2022-07-25
CVE-2022-23302 JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to... 8.8 - HIGH 2022-01-18 2022-07-25
CVE-2021-4104 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j c... 8.8 - HIGH 2021-12-14 2022-09-07
CVE-2020-9493 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. 9.8 - CRITICAL 2021-06-16 2022-04-08
CVE-2020-9488 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to ... 3.7 - LOW 2020-04-27 2022-05-12
CVE-2019-17571 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited ... 9.8 - CRITICAL 2019-12-20 2022-07-25
CVE-2017-5645 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from... 9.8 - CRITICAL 2017-04-17 2022-04-04

