An open API service providing security vulnerability metadata for many open source software ecosystems.

maven

org.apache.logging.log4j:log4j

maven

Apache Log4j Parent

View on github.com · View on repo1.maven.org

Security Advisories for org.apache.logging.log4j:log4j in maven

Potential
High
over 4 years ago

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data GSA_kwCzR0hTQS1mcDVyLXYzdzktNDMzM80bRA

maven org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Potential
Critical
over 4 years ago

Remote code injection in Log4j GSA_kwCzR0hTQS1qZmg4LWMyanAtNXYzcc0asw

maven uk.co.nichesolutions.logging.log4j:log4j-core, org.xbib.elasticsearch:log4j, com.guicedee.services:log4j-core, org.apache.logging.log4j:log4j-core
Low
about 6 years ago

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ3cXEtNXZyYy14dzlo

maven org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j