Apache log4j 1.x
This hub aggregates every CVE we track for Apache log4j 1.x, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 4 most recently published vulnerabilities affecting Apache log4j 1.x.
- CVE-2022-23307A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.8.8
- CVE-2022-23305SQL injection in JDBC Appender in Apache Log4j V19.8
- CVE-2022-23302Deserialization of untrusted data in JMSSink in Apache Log4j 1.x8.8
- CVE-2021-4104Deserialization of untrusted data in JMSAppender in Apache Log4j 1.27.5
Product normalization is registry-driven with AI assist and human review. How it works