Artifact: log4j:log4j:1.2.17
Original JDK Target
Java 1.4 (Class file major/minor version 48.0). Built to run on JDK 1.4 through JDK 8. When executing directly under Java 21 without upgrading, strong Java Platform Module System (JPMS) encapsulation blocks reflection into internal JDK APIs unless explicit command-line flags are configured.
Vulnerabilities & Security Risks
End-of-Life (EOL) since August 2015 with severe unpatched vulnerabilities:
-
CVE-2019-17571 (CVSS 9.8): Remote Code Execution (RCE) via untrusted deserialization in
SocketServer. -
CVE-2021-4104: Deserialization vulnerability when configured to use
JMSAppender. -
CVE-2022-23302: Deserialization vulnerability when configured to use
JMSSink. -
CVE-2022-23305 (CVSS 9.8): SQL Injection in
JDBCAppender.
Recommended Strategy
Upgrade to Log4j 2.x using the log4j-1.2-api bridge.
xml
<dependency>
<groupId>org.apache.logging.log4j</groupId>
<artifactId>log4j-1.2-api</artifactId>
<version>2.23.1</version>
</dependency>
Top comments (0)