Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Vendor: Apache
Product: Log4j2
Added: 2023-05-01
Due Date: 2023-05-22
Description:
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Required Action:
Apply updates per vendor instructions.
CWEs: