Lucene search

K
osvGoogleOSV:GHSA-FXPH-Q3J8-MV87
HistoryJan 06, 2020 - 6:43 p.m.

Deserialization of Untrusted Data in Log4j

2020-01-0618:43:38
Google
osv.dev
49

EPSS

0.874

Percentile

98.7%

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

References