An open API service providing security vulnerability metadata for many open source software ecosystems.

maven

org.apache.logging.log4j:log4j-core

maven

The Apache Log4j Implementation

View on github.com · View on repo1.maven.org

Security Advisories for org.apache.logging.log4j:log4j-core in maven

High
over 3 years ago

Apache Log4j 1.x (EOL) allows Denial of Service (DoS) GSA_kwCzR0hTQS12cDk4LXcycDMtbXYzNc4AAyBx

maven org.apache.logging.log4j:log4j-core
Moderate
over 4 years ago

Improper Input Validation and Injection in Apache Log4j2 GSA_kwCzR0hTQS04NDg5LTQ0bXYtZ2dqOM0fsA

maven org.apache.logging.log4j:log4j-core
Potential
High
over 4 years ago

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data GSA_kwCzR0hTQS1mcDVyLXYzdzktNDMzM80bRA

maven org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Critical
over 4 years ago

Incomplete fix for Apache Log4j vulnerability GSA_kwCzR0hTQS03cmpyLTNxNTUtdnYzM80bQA

maven org.apache.logging.log4j:log4j-core
Critical
over 4 years ago

Remote code injection in Log4j GSA_kwCzR0hTQS1qZmg4LWMyanAtNXYzcc0asw

maven uk.co.nichesolutions.logging.log4j:log4j-core, org.xbib.elasticsearch:log4j, com.guicedee.services:log4j-core, org.apache.logging.log4j:log4j-core
Low
about 6 years ago

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ3cXEtNXZyYy14dzlo

maven org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j