Lucene search

K
osvGoogleOSV:USN-5223-1
HistoryJan 12, 2022 - 7:31 p.m.

apache-log4j1.2 vulnerability

2022-01-1219:31:51
Google
osv.dev
12

7.8 High

AI Score

Confidence

Low

0.127 Low

EPSS

Percentile

95.5%

It was discovered that Apache Log4j 1.2 was vulnerable to deserialization of
untrusted data if the configuration file was editable. An attacker could use
this vulnerability to cause a DoS or possibly execute arbitrary code.