← Back to browse · API

CVE-2019-17571

Severity
CRITICAL
CVSS
9.8
EPSS
0.6906
Risk score
63.37
CISA KEV
No
PoC
No
Published
2019-12-20
Modified
2026-05-28
First seen
2026-08-07
Aliases
EUVD-2020-0246, GHSA-2QRG-X229-3V8Q
Products
Apache Software Foundation:Log4j versions up to 1.2.17
Sources
euvd EUVD-2020-0246

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

References