{"id":"GHSA-f7vh-qwp3-x37m","summary":"Deserialization of Untrusted Data in Apache Log4j","details":"CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.\n\nUsers are advised to migrate from `log4j:log4j` to `org.apache.logging.log4j:log4j` for an updated version of the library.","aliases":["CVE-2022-23307"],"modified":"2023-11-01T05:44:47.251202Z","published":"2022-01-19T00:01:15Z","database_specific":{"github_reviewed_at":"2022-06-20T22:48:35Z","nvd_published_at":"2022-01-18T16:15:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23307"},{"type":"WEB","url":"https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh"},{"type":"WEB","url":"https://logging.apache.org/log4j/1.2/index.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"package":{"name":"log4j:log4j","ecosystem":"Maven","purl":"pkg:maven/log4j/log4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.2.17"}]}],"versions":["1.1.3","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-f7vh-qwp3-x37m/GHSA-f7vh-qwp3-x37m.json"}},{"package":{"name":"org.zenframework.z8.dependencies.commons:log4j-1.2.17","ecosystem":"Maven","purl":"pkg:maven/org.zenframework.z8.dependencies.commons/log4j-1.2.17"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.0"}]}],"versions":["2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-f7vh-qwp3-x37m/GHSA-f7vh-qwp3-x37m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}