Junglewise Threat Intelligence

CVE-2022-23307: Deserialization of Untrusted Data in Apache Log4j

CVE-2022-23307 · Severity: low · CVSS 3.1 · Published 2022-01-19

Technologies: org.zenframework.z8.dependencies.commons:log4j-1.2.17 (Maven), log4j:log4j (Maven). Vendors: Maven.

Executive brief

Deserialization of Untrusted Data in Apache Log4j

Affected products

  • Maven org.zenframework.z8.dependencies.commons:log4j-1.2.17
  • Maven log4j:log4j

Related threats