Deserialization of Untrusted Data in Apache Log4j
Critical severity
GitHub Reviewed
Published
Jan 19, 2022
to the GitHub Advisory Database
•
Updated Oct 31, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 19, 2022
Reviewed
Jun 20, 2022
Last updated
Oct 31, 2023
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from
log4j:log4j
toorg.apache.logging.log4j:log4j
for an updated version of the library.References