In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.logging.log4j:log4j(Maven) | 2.0 | 2.8.2 | N/A |
| org.apache.logging.log4j:log4j-core(Maven) | 2.0 | 2.8.2 | N/A |
CVSS Metrics