Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68161

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:

  • The attacker is able to intercept or redirect network traffic between the client and the log receiver.
  • The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.

    A flaw was found in Apache Log4j Core. The Socket Appender component fails to perform proper TLS (Transport Layer Security) hostname verification of peer certificates. This vulnerability allows a man-in-the-middle (MITM) attacker to intercept or redirect log traffic, potentially leading to information disclosure. Exploitation requires the attacker to intercept network traffic and present a server certificate issued by a trusted certification authority.

Отчет

This vulnerability is rated Moderate for Red Hat products utilizing Apache Log4j Core versions 2.0-beta9 through 2.25.2 with the Socket Appender configured for TLS. The flaw allows a man-in-the-middle attacker to intercept or redirect log traffic due to missing TLS hostname verification, provided the attacker can intercept network traffic and present a trusted certificate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientslog4j-coreFix deferred
Logging Subsystem for Red Hat OpenShiftlog4j-coreFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis-preview/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=2423705Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification

EPSS

Процентиль: 10%
0.00034
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. A...

CVSS3: 4.8
nvd
3 месяца назад

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this i

msrc
3 месяца назад

Apache Log4j Core: Missing TLS hostname verification in Socket appender

CVSS3: 4.8
debian
3 месяца назад

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2. ...

suse-cvrf
2 месяца назад

Security update for log4j

EPSS

Процентиль: 10%
0.00034
Низкий

5.9 Medium

CVSS3