Lucene search

K
f5F5F5:K00322972
HistoryJan 31, 2022 - 12:00 a.m.

K00322972 : Apache Log4j Chainsaw vulnerability CVE-2022-23307

2022-01-3100:00:00
my.f5.com
220

9 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.4%

Security Advisory Description

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. (CVE-2022-23307)

Impact

An attacker may be able to use this vulnerability to generate a Log4j configuration that allows them to perform unauthorized actions.