pkg:Maven/log4j:log4j

6 total CVEsCRITICAL3HIGH3

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2022-23305SQL Injection in Log4j 1.2.x
    from 0, <= 1.2.17
  • CRITICAL9.8CVE-2022-23307Deserialization of Untrusted Data in Apache Log4j
    from 0, <= 1.2.17
  • CRITICAL9.8CVE-2019-17571apache-log4j1.2 - security update
    >= 1.2, <= 1.2.17
  • HIGH8.8CVE-2022-23302Deserialization of Untrusted Data in Log4j 1.x
    from 0, <= 1.2.17
  • HIGH7.5CVE-2023-26464Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
    >= 1.0.4, < 2.0
  • HIGH7.5CVE-2021-4104apache-log4j1.2 - security update
    >= 1.2.0, <= 1.2.17