log4j

apache/log4j: The latest CVE Vulnerabilities and Exploits for Penetration Test

apache/log4j Vulnerability Summary Vendor name: apache Product name: log4j Total vulnerabilities: 11 (as 2023-05-04) apache/log4j Vulnerability List CVE-2022-23302: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the… Published: 2022-01-18T16:15:00 Last Modified: 2022-01-27T16:21:00 Summary JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to.