Описание
ELSA-2022-0442: log4j security update (IMPORTANT)
[0:1.2.17-18]
- Fix Unsafe deserialization flaw in Chainsaw log viewer
- Fix SQL injection when application is configured to use JDBCAppender
- Fix remote code execution when application is configured to use JMSSink
- Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-23302
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
log4j
1.2.17-18.el7_4
log4j-javadoc
1.2.17-18.el7_4
log4j-manual
1.2.17-18.el7_4
Oracle Linux x86_64
log4j
1.2.17-18.el7_4
log4j-javadoc
1.2.17-18.el7_4
log4j-manual
1.2.17-18.el7_4