DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8wrm-wc9c-gxxw

Published

Last updated

https://images.chainguard.dev/security/CGA-8wrm-wc9c-gxxw
Package

druid

Latest Update
Pending upstream fix
Aliases
  • CVE-2019-17571
  • GHSA-2qrg-x229-3v8q

Severity

9.8

Critical

CVSS V3

Summary

Deserialization of Untrusted Data in Log4j

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17.

Users are advised to migrate to org.apache.logging.log4j:log4j-core.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images