[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5024-1 apache-log4j2 -- liblog4j2-java

ID: oval:org.secpod.oval:def:76503Date: (C)2021-12-21   (M)2023-11-10
Class: PATCHFamily: unix




It was found that Apache Log4j2, a Logging Framework for Java, did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup , attackers with control over Thread Context Map input data can craft malicious input data that contains a recursive lookup, resulting in a denial of service.

Platform:
Linux Mint 4
Product:
liblog4j2-java
Reference:
DSA-5024-1
CVE-2021-45105
CVE    1
CVE-2021-45105

© SecPod Technologies