GHSA-mf4f-j588-5xm8
CRITICALOpencast uses an Apache Log4j2 version which, combined with older JDK versions, can be used for remote code execution attacks which have been found to be actively exploited.
- Affected
- >= 10.0, < 10.6, < 9.10
- Fixed in
- 10.6
- Published
- 2021-12-14
- Source
- github