GHSA-fxph-q3j8-mv87
CRITICALCVE-2017-5645In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
- Affected
- >= 2.0, < 2.8.2
- Fixed in
- 2.8.2
- Weakness
- CWE-502
- Published
- 2020-01-06
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference