JDBCAppender in Log4j is vulnerable to SQL Injection. An attacker is able to execute arbitrary SQL commands via entering crafted strings into input fields and headers where the values to be inserted are converters from PatternLayout
CVE
2022-23305
CVSS score
6.8
Vulnerability present in version/s
1.1.3-1.2.17
Found library version/s
1.2.17
Vulnerability fixed in version
Library latest version
1.2.17
Fix
No fix is released. Users should upgrade to Log4j 2 or remove usage of the JDBCAppender from their configurations
Veracode Software Composition Analysis
PatternLayout
Links: