CVE-2022-23307
CRITICAL9.8EPSS 2.6%Deserialization of Untrusted Data in Apache Log4j
Published: 1/19/2022Modified: 4/28/2026
Description
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Affected packages (3)
- Debian/apache-log4j1.2from 0, < 1.2.17-10+deb11u1
- Maven/log4j:log4jfrom 0, <= 1.2.17
- Maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17from 0, <= 2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-23307
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-23307
- WEBhttps://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
- WEBhttps://logging.apache.org/log4j/1.2/index.html
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2022.html