PT-2022-1423 · Apache+9 · Log4J+9

Published

2022-01-10

·

Updated

2026-05-27

·

CVE-2022-23302

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Log4j versions 1.x
Description The issue is related to the deserialization of untrusted data in the JMSSink component of Log4j 1.x, which can lead to remote code execution when the attacker has write access to the Log4j configuration or access to an LDAP service referenced in the configuration. This can be achieved by providing a specially crafted TopicConnectionFactoryBindingName configuration, causing JMSSink to perform JNDI requests. The issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. It is noted that Apache Log4j 1.2 reached end of life in August 2015.
Recommendations For Log4j versions 1.x, upgrade to Log4j 2 to address this and numerous other issues from the previous versions. As a temporary workaround, consider disabling the use of JMSSink until a patch is available. Restrict access to the Log4j configuration to minimize the risk of exploitation. Avoid using the TopicConnectionFactoryBindingName configuration in the affected Log4j 1.x versions until the issue is resolved.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0290
BDU:2022-00526
CESA-2022_0290
CESA-2022_0442
CVE-2022-23302
DLA-2905-1
GHSA-W9P3-5CR8-M3JJ
MGASA-2023-0141
OESA-2022-1513
OESA-2022-2065
OPENSUSE-SU-2022:0038-1
OPENSUSE-SU-2022:0214-1
OPENSUSE-SU-2022:0226-1
OPENSUSE-SU-2022_0040-1
OPENSUSE-SU-2022_0214-1
OPENSUSE-SU-2022_0226-1
OPENSUSE-SU-2024:11759-1
OPENSUSE-SU-2024:11838-1
RHSA-2022:0289
RHSA-2022:0290
RHSA-2022:0291
RHSA-2022:0294
RHSA-2022:0436
RHSA-2022:0438
RHSA-2022:0439
RHSA-2022:0442
RHSA-2022:0447
RHSA-2022:0448
RHSA-2022:0475
RHSA-2022:0524
RHSA-2022:1296
RHSA-2022:1297
RHSA-2022:5459
RHSA-2022:5460
RHSA-2022_0290
RHSA-2022_0442
RHSA-2024:5856
RLSA-2022:0290
ROSA-SA-2024-2519
SUSE-SU-2022:0212-1
SUSE-SU-2022:0214-1
SUSE-SU-2022:0226-1
SUSE-SU-2022:0354-1
SUSE-SU-2022:0355-1
SUSE-SU-2022:14881-1
SUSE-SU-2022_0212-1
SUSE-SU-2022_0214-1
SUSE-SU-2022_0226-1
SUSE-SU-2022_14881-1
USN-5998-1
USN-7590-1

Affected Products

Almalinux
Astra Linux
Centos
Jira
Linuxmint
Log4J
Red Hat
Rocky Linux
Suse
Ubuntu