DEV Community

Query Filter
Query Filter

Posted on

word-5

Artifact: log4j:log4j:1.2.17

Original JDK Target

Java 1.4 (Class file major/minor version 48.0). Built to run on JDK 1.4 through JDK 8. When executing directly under Java 21 without upgrading, strong Java Platform Module System (JPMS) encapsulation blocks reflection into internal JDK APIs unless explicit command-line flags are configured.

Vulnerabilities & Security Risks

End-of-Life (EOL) since August 2015 with severe unpatched vulnerabilities:

  • CVE-2019-17571 (CVSS 9.8): Remote Code Execution (RCE) via untrusted deserialization in SocketServer.
  • CVE-2021-4104: Deserialization vulnerability when configured to use JMSAppender.
  • CVE-2022-23302: Deserialization vulnerability when configured to use JMSSink.
  • CVE-2022-23305 (CVSS 9.8): SQL Injection in JDBCAppender.

Recommended Strategy

Upgrade to Log4j 2.x using the log4j-1.2-api bridge.


xml
<dependency>
    <groupId>org.apache.logging.log4j</groupId>
    <artifactId>log4j-1.2-api</artifactId>
    <version>2.23.1</version>
</dependency>
Enter fullscreen mode Exit fullscreen mode

Top comments (0)