Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33763
HistoryJan 19, 2022 - 8:50 a.m.

Deserialisation Of Untrusted Object

2022-01-1908:50:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.005 Low

EPSS

Percentile

77.5%

JMSSink in log4j is vulnerable to deserialization of untrusted object. The insecure use of JNDI in JMSSink allows an attacker to send malicious object in LDAP store if it is accessible by an attacker or is configured to use an untrusted site, leading to a remote code execution. Note: this vulnerability only affects the applications specifically configured to use JMSSink, which is not the default.