qos-ch / reload4j

reload4j is a drop-in replacement for log4j 1.2.17
Apache License 2.0
148 stars 22 forks source link

Fix CVE-2020-9493 and CVE-2022-23307 (Chainsaw deserialization) #21

Closed ceki closed 2 years ago

ceki commented 2 years ago

Here are some relevant links:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9493 https://nvd.nist.gov/vuln/detail/CVE-2022-23307 https://lists.apache.org/thread/rx0hpjow5csq05r93cyvntj9ry19tm9y

The issue seems to stem from uncontrolled deserialization.

ceki commented 2 years ago

Fixed in 64902fe18ce5 by hardening the code and not removing it.