CVE-2019-17571

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 ...

critical 9.8 CVSS 3.1
Published: Dec 20, 2019
Modified: May 28, 2026
Vendor: Apache
Product: Log4J
Versions: 8.0,9.0,10.0,18.04,15.1,13.3.0.1,3.2.0,12.5.0,12.1,12.2

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

References

Related CVEs