Package impact
Maven / log4j:log4j
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2022-23307 | high | 8.8 | 8.8 | 4y ago | Deserialization of Untrusted Data in Apache Log4j | |
| CVE-2022-23302 | high | 8.8 | 8.8 | 4y ago | Deserialization of Untrusted Data in Log4j 1.x | |
| CVE-2021-4104 | high | — | 8.0 | 5y ago | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data | |
| CVE-2023-26464 | unknown | — | — | 3y ago | Apache Log4j 1.x (EOL) allows Denial of Service (DoS) |