CVE-2019-17571
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
- Apache log4j
- ≤ 1.2.17
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 69.1% (99th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2019-12-20
CVE-2019-17571 at NVD
3 known exploits for CVE-2019-17571
Proof-of-concept code and exploit modules indexed by Sploitus