Junglewise Threat Intelligence

CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data

CVE-2021-4104 · Severity: low · CVSS 3.1 · Published 2021-12-14

Technologies: org.zenframework.z8.dependencies.commons:log4j-1.2.17 (Maven), log4j:log4j (Maven). Vendors: Maven.

Executive brief

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data

Affected products

  • Maven org.zenframework.z8.dependencies.commons:log4j-1.2.17
  • Maven log4j:log4j

Related threats