Описание
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the logger application.
Отчет
The flaw in Log4j-1.x is now identified by CVE-2019-17571. CVE-2017-5645 has been assigned by MITRE to a similar flaw identified in Log4j-2.x
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat AMQ Broker 7 | hawtio-osgi | Affected | ||
Red Hat Enterprise Linux 5 | log4j | Will not fix | ||
Red Hat Enterprise Linux 6 | log4j | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | log4j | Not affected | ||
Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Will not fix | ||
Red Hat Fuse 7 | log4j | Affected | ||
Red Hat JBoss A-MQ 6 | log4j | Affected | ||
Red Hat JBoss BRMS 5 | log4j | Will not fix | ||
Red Hat JBoss Data Grid 7 | log4j-core | Affected | ||
Red Hat JBoss Data Virtualization 6 | log4j | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or ...
EPSS
8.1 High
CVSS3