rpm package
opensuse/log4j-mini&distro=openSUSE Leap 15.1
pkg:rpm/opensuse/log4j-mini&distro=openSUSE%20Leap%2015.1
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-17571 | Cri | 9.8 | < 1.2.17-lp151.5.3.1 | 1.2.17-lp151.5.3.1 | Dec 20, 2019 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j |
- affected < 1.2.17-lp151.5.3.1fixed 1.2.17-lp151.5.3.1
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j