forked from jtsmith2020/verademo-java
-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
Severity: HighHigh severityHigh severityVeracode Dependency ScanningA Veracode identified vulnerabilityA Veracode identified vulnerability
Description
Veracode Software Composition Analysis
| Attribute | Details |
|---|---|
| Library | Apache Log4j |
| Description | Apache Log4j 1.2 |
| Language | JAVA |
| Vulnerability | SQL Injection |
| Vulnerability description | JDBCAppender in Log4j is vulnerable to SQL injection attacks. An attacker is able to execute arbitrary SQL commands via entering crafted strings into input fields and headers where the values to be inserted are converters from PatternLayout |
| CVE | 2022-23305 |
| CVSS score | 6.8 |
| Vulnerability present in version/s | 1.1.3-1.2.17 |
| Found library version/s | 1.2.17 |
| Vulnerability fixed in version | |
| Library latest version | 1.2.17 |
| Fix | No fix is released. Users should upgrade to Log4j 2 or remove usage of the JDBCAppender from their configurations |
Links:
Metadata
Metadata
Assignees
Labels
Severity: HighHigh severityHigh severityVeracode Dependency ScanningA Veracode identified vulnerabilityA Veracode identified vulnerability