Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Upgrade to Apache Log4j 2 and Apache Chainsaw 2.1.0.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2905-1 | apache-log4j1.2 security update |
EUVD |
EUVD-2022-0575 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. |
Github GHSA |
GHSA-f7vh-qwp3-x37m | Deserialization of Untrusted Data in Apache Log4j |
Ubuntu USN |
USN-5998-1 | Apache Log4j vulnerabilities |
Ubuntu USN |
USN-7590-1 | Apache Log4j vulnerabilities |
Tue, 24 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution. | A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 25 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 26 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T03:36:20.396Z
Reserved: 2022-01-17T00:00:00.000Z
Link: CVE-2022-23307
No data.
Status : Modified
Published: 2022-01-18T16:15:08.403
Modified: 2024-11-21T06:48:22.733
Link: CVE-2022-23307
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN