Search CVE reports
1 – 10 of 12 results
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j1.2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j1.2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j1.2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j1.2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the ...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 11
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | Needs evaluation | Not affected | Fixed | Fixed |
Some fixes available 4 of 5
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | Not affected | Not affected | Fixed | Fixed |
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | — | Not affected | Fixed | Not affected |
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other...
1 affected package
apache-log4j2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| apache-log4j2 | — | Not affected | Fixed | Fixed |