Skip to content

CVE-2017-5645 (High) detected in log4j-core-2.7.jar #5

@mend-for-github-com

Description

@mend-for-github-com

CVE-2017-5645 - High Severity Vulnerability

Vulnerable Library - log4j-core-2.7.jar

The Apache Log4j Implementation

Path to dependency file: /pom.xml

Path to vulnerable library: /canner/.m2/repository/org/apache/logging/log4j/log4j-core/2.7/log4j-core-2.7.jar

Dependency Hierarchy:

  • log4j-core-2.7.jar (Vulnerable Library)

Found in HEAD commit: 23bb74a3a396f24547965c7d26392761919d40ec

Found in base branch: master

Vulnerability Details

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Publish Date: 2017-04-17

URL: CVE-2017-5645

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5645

Release Date: 2017-04-17

Fix Resolution: org.apache.logging.log4j:log4j-core:2.8.2


⛑️ Automatic Remediation is available for this issue

Metadata

Metadata

Assignees

No one assigned

    Labels

    security vulnerabilitySecurity vulnerability detected by WhiteSource

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions