PT-2021-24476 · Unknown · Pax-Logging

Published

2021-12-10

·

Updated

2021-12-10

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: pax-logging versions 1.11.9 pax-logging versions 2.0.10
Description: The issue allows for Remote Code Execution. Users can set the system property -Dlog4j2.formatMsgNoLookups=true as a workaround.
Recommendations: For pax-logging version 1.11.9, update to version 1.11.10. For pax-logging version 2.0.10, update to version 2.0.11. As a temporary workaround, consider setting the system property -Dlog4j2.formatMsgNoLookups=true to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-XXFH-X98P-J8FR

Affected Products

Pax-Logging