CVE Published: 20/12/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: apache |
Vendor: Apache Software Foundation |
Product: Log4j Status : PUBLISHED
CVE-2019-17571 Description
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.