org.apache.logging.log4j:log4j-core
The Apache Log4j Implementation
Security Advisories for org.apache.logging.log4j:log4j-core in maven
Moderate
4 months ago
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
maven
org.apache.logging.log4j:log4j-core
Moderate
4 months ago
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
maven
org.apache.logging.log4j:log4j-core
Moderate
4 months ago
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
maven
org.apache.logging.log4j:log4j-core
Moderate
8 months ago
Apache Log4j does not verify the TLS hostname in its Socket Appender
maven
org.apache.logging.log4j:log4j-core
High
over 3 years ago
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
maven
org.apache.logging.log4j:log4j-core
Moderate
over 4 years ago
Improper Input Validation and Injection in Apache Log4j2
maven
org.apache.logging.log4j:log4j-core
High
over 4 years ago
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
maven
org.apache.logging.log4j:log4j-core
Potential
High
over 4 years ago
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
maven
org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Critical
over 4 years ago
Incomplete fix for Apache Log4j vulnerability
maven
org.apache.logging.log4j:log4j-core
Critical
over 4 years ago
Remote code injection in Log4j
maven
uk.co.nichesolutions.logging.log4j:log4j-core, org.xbib.elasticsearch:log4j, com.guicedee.services:log4j-core, org.apache.logging.log4j:log4j-core
Low
about 6 years ago
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
maven
org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j