CVE-2022-23307
CRITICAL9.8EPSS 2.6%Deserialization of Untrusted Data in Apache Log4j
發布日:2022/1/19修改日:2026/4/28
描述
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
受影響套件(3)
- Debian/apache-log4j1.2from 0, < 1.2.17-10+deb11u1
- Maven/log4j:log4jfrom 0, <= 1.2.17
- Maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17from 0, <= 2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-23307
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-23307
- WEBhttps://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
- WEBhttps://logging.apache.org/log4j/1.2/index.html
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2022.html