Lucene search

K
redhatcveRedhat.comRH:CVE-2017-5645
HistoryOct 10, 2019 - 10:12 a.m.

CVE-2017-5645

2019-10-1010:12:57
redhat.com
access.redhat.com
30

0.874 High

EPSS

Percentile

98.7%

It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the logger application.