org.apache.logging.log4j
log4j-core
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
pkg:maven/org.apache.logging.log4j/log4j-core?type=jar
CVE-2021-44832
6.6
medium
CVSSv3
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
20
74
2021-12-28T00:00:00Z
2021-12-28T00:00:00Z
2022-08-08T00:00:00Z
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-beta7|<2.3.2]]>
=2.4|<2.12.4]]>
=2.13.0|<2.17.1]]>
CVE-2021-45105
LOG4J2-3230
5.9
medium
CVSSv3
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
20
674
2021-12-18T00:00:00Z
2021-12-18T00:00:00Z
2022-10-06T00:00:00Z
Hideki Okamoto
Guy Lederfein
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-alpha1|<2.3.1]]>
=2.4|<2.12.3]]>
=2.13.0|<2.17.0]]>
CVE-2021-45046
LOG4J2-3221
9.0
critical
CVSSv3
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
917
2021-12-14T00:00:00Z
2021-12-14T00:00:00Z
2023-10-26T00:00:00Z
Kai Mindermann
4ra1n
Ash Fox
Alvaro Muñoz
Tony Torralba
Anthony Weems
RyotaK
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-beta9|<2.3.1]]>
=2.4|<2.12.3]]>
=2.13.0|<2.17.0]]>
CVE-2021-44228
LOG4J2-3198
LOG4J2-3201
10.0
critical
CVSSv3
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
20
400
502
917
2021-12-10T00:00:00Z
2021-12-10T00:00:00Z
2023-04-03T00:00:00Z
Chen Zhaojun
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-beta9|<2.3.1]]>
=2.4|<2.12.3]]>
=2.13.0|<2.17.0]]>
CVE-2020-9488
LOG4J2-2819
3.7
low
CVSSv3
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
295
2017-04-27T00:00:00Z
2017-04-27T00:00:00Z
2022-05-12T00:00:00Z
Peter Stöckli
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-beta1|<2.12.3]]>
CVE-2017-5645
LOG4J2-1863
the security fix commit
7.5
high
CVSSv2
AV:N/AC:L/Au:N/C:P/I:P/A:P
502
2017-04-17T00:00:00Z
2017-04-17T00:00:00Z
2022-04-04T00:00:00Z
Marcio Almeida de Macedo
[pkg:maven/org.apache.logging.log4j/log4j-core?type=jar]
=2.0-alpha1|<2.8.2]]>