apache / apache/dubbo

Log4j 1.x 版本的漏洞CVE-2022-23302/23305/23307是否涉及

Open
#9,609 1 comment 0 reactions 0 assignees View on GitHub
type/discussion
Dominant language
Java
Stars
41.6k
Forks
26.4k
Avg merge
15h 13m
Merged PRs (30d)
4

Description

2022年01月20日,PSIRT监测发现Apache官方 发布了Log4j(1.x版本)的风险通告,漏洞编号为CVE-2022-23302,CVE-2022-23305,CVE-2022-23307,对应的组件分别是:JMSSink、JDBCAppender、Chainsaw。漏洞等级:严重,漏洞评分:9.8。这几个漏洞仅影响Log4j 1.x版本,Log4j 2版本均不受影响。

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by checking whether this Java project uses Log4j 1.x and whether JMSSink, JDBCAppender, or Chainsaw are present; confirm whether the three listed CVEs affect the project and document the impact or conclusion.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.