All vulnerabilities

CVE-2022-23307

Deserialization of Untrusted Data in Apache Log4j

Description

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Users are advised to migrate from log4j:log4j to org.apache.logging.log4j:log4j for an updated version of the library.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
Java
Publish Date
January 18, 2022
Modified Date
February 16, 2024
Score Vector
Affected Versions