Junglewise Threat Intelligence

CVE-2022-23302: Deserialization of Untrusted Data in Log4j 1.x

CVE-2022-23302 · Severity: low · CVSS 3.1 · Published 2022-01-21

Technologies: org.zenframework.z8.dependencies.commons:log4j-1.2.17 (Maven), log4j:log4j (Maven). Vendors: Maven.

Executive brief

Deserialization of Untrusted Data in Log4j 1.x

Affected products

  • Maven org.zenframework.z8.dependencies.commons:log4j-1.2.17
  • Maven log4j:log4j

Related threats