Package impact
Maven / log4j:log4j
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23305 | critical | 9.8 | 9.8 | 4y ago | RHSA-2022:0290: parfait:0.5 security update (Important) | |||
| CVE-2019-17571 | critical | 9.8 | 9.8 | 7y ago | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization ga… | |||
| CVE-2022-23307 | high | 8.8 | 8.8 | 4y ago | RHSA-2022:0290: parfait:0.5 security update (Important) | |||
| CVE-2022-23302 | high | 8.8 | 8.8 | 4y ago | RHSA-2022:0290: parfait:0.5 security update (Important) | |||
| CVE-2021-4104 | high | 7.5 | 7.5 | 5y ago | RHSA-2022:0290: parfait:0.5 security update (Important) |