Back to search
CVE-2022-23307
Published: Jan 18, 2022
Modified: May 27, 2026
PUBLISHED
Description
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Log4j 1.x | affected 1.2.1 - < unspecifiedaffected unspecified - <= 2.0-alpha1 |
Weaknesses (CWE)
References
https://logging.apache.org/log4j/1.2/index.html
x_refsource_MISC
https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
x_refsource_MISC
https://www.oracle.com/security-alerts/cpuapr2022.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpujul2022.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now