CVE-2020-9493
published 2022-01-18CVE-2020-9493: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.61%
90.6th percentile
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | chainsaw | < 2.1.0 | 2.1.0 |
| apache | log4j | >= 1.2 < 2.0 | 2.0 |
| apache_software_foundation | apache_log4j_1.x | >= 1.2.1 < unspecified | unspecified |
| apache_software_foundation | apache_log4j_1.x | unspecified – 2.0-alpha1 | — |
| debian | apache-log4j1.2 | < apache-log4j1.2 1.2.17-11 (bookworm) | apache-log4j1.2 1.2.17-11 (bookworm) |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_eagle_ftp_table_base_retrieval | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_offline_mediation_controller | < 12.0.0.4.4 | 12.0.0.4.4 |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | < 2.2.1.1.1 | 2.2.1.1.1 |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | financial_services_revenue_management_and_billing_analytics | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-prp9-9gxw-38j8: A deserialization flaw was found in Apache Chainsaw versions prior to 2
ghsa_unreviewed·2022-05-24
CVE-2020-9493 [CRITICAL] CWE-502 GHSA-prp9-9gxw-38j8: A deserialization flaw was found in Apache Chainsaw versions prior to 2
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
OSV
Deserialization of Untrusted Data in Apache Log4j
osv·2022-01-19·CVSS 9.8
CVE-2022-23307 [CRITICAL] Deserialization of Untrusted Data in Apache Log4j
Deserialization of Untrusted Data in Apache Log4j
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from `log4j:log4j` to `org.apache.logging.log4j:log4j` for an updated version of the library.
GHSA
Deserialization of Untrusted Data in Apache Log4j
ghsa·2022-01-19·CVSS 9.8
CVE-2022-23307 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Apache Log4j
Deserialization of Untrusted Data in Apache Log4j
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from `log4j:log4j` to `org.apache.logging.log4j:log4j` for an updated version of the library.
OSV
CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw
osv·2022-01-18·CVSS 9.8
CVE-2022-23307 [CRITICAL] CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Red Hat
log4j: Unsafe deserialization flaw in Chainsaw log viewer
vendor_redhat·2022-01-18·CVSS 9.8
CVE-2022-23307 [CRITICAL] CWE-502 log4j: Unsafe deserialization flaw in Chainsaw log viewer
log4j: Unsafe deserialization flaw in Chainsaw log viewer
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
A flaw was found in the log4j 1.x chainsaw component, where the contents of certain log entries are deserialized and possibly permit code execution. This flaw allows an attacker to send a malicious request with serialized data to the server to be deserialized when the chainsaw component is run.
Statement: Chainsaw is a standalone graphical user interface for viewing log entries in log4j. This flaw may be bypassed by using other available means to access log entries.
Red Hat Satellite bundles log4j-over-slf4j with Candlepin, however, product is not
Debian
CVE-2022-23307: apache-log4j1.2 - CVE-2020-9493 identified a deserialization issue that was present in Apache Chai...
vendor_debian·2022·CVSS 9.8
CVE-2022-23307 [CRITICAL] CVE-2022-23307: apache-log4j1.2 - CVE-2020-9493 identified a deserialization issue that was present in Apache Chai...
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Scope: local
bookworm: resolved (fixed in 1.2.17-11)
bullseye: resolved (fixed in 1.2.17-10+deb11u1)
forky: resolved (fixed in 1.2.17-11)
sid: resolved (fixed in 1.2.17-11)
trixie: resolved (fixed in 1.2.17-11)
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhhhttps://logging.apache.org/log4j/1.2/index.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhhhttps://logging.apache.org/log4j/1.2/index.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-01-18
Published