PublicCVE

CVE-2017-5645

UNRATED
Public PoCHigh EPSS
JSON exportCreate alert

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Affected products

Exploits & PoCs

References