cbcvebase.
CVE-2022-23307
published 2022-01-18

CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x…

PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
52.46%
98.8th percentile
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
apachechainsaw< 2.1.02.1.0
apachelog4j>= 1.2 < 2.02.0
debianapache-log4j1.2< apache-log4j1.2 1.2.17-11 (bookworm)apache-log4j1.2 1.2.17-11 (bookworm)
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
oracleadvanced_supply_chain_planning
oracleadvanced_supply_chain_planning
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_eagle_ftp_table_base_retrieval
oraclecommunications_instant_messaging_server
oraclecommunications_messaging_server
oraclecommunications_network_integrity
oraclecommunications_offline_mediation_controller< 12.0.0.4.412.0.0.4.4
oraclecommunications_offline_mediation_controller
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclee-business_suite_cloud_manager_and_cloud_backup_module< 2.2.1.1.12.2.1.1.1
oraclee-business_suite_cloud_manager_and_cloud_backup_module
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclefinancial_services_revenue_management_and_billing_analytics
oraclefinancial_services_revenue_management_and_billing_analytics

Detection & IOCsextracted from sources · hover to see the quote

pathorg/apache/log4j/chainsaw/*
  • CVE-2022-23307 is the same vulnerability as CVE-2020-9493 — the Chainsaw component of Apache Log4j 1.2.x performs unsafe deserialization of log events, enabling remote code execution. Detection should focus on Chainsaw being invoked alongside log4j 1.2.x.
  • The attack vector requires an attacker to send a malicious request containing serialized data to a server running the Chainsaw component; monitor for unexpected deserialization activity in processes associated with log4j 1.2.x Chainsaw.
  • Log4j 1.2.x (end-of-life since August 2015) is the affected version range; inventory applications using Log4j versions 1.2.x as a detection/triage signal.
  • ·The vulnerability only manifests when the Chainsaw component is actively run; products shipping log4j 1.2.x but not using Chainsaw are not exploitable via this vector.
  • ·Red Hat Satellite bundles log4j-over-slf4j with Candlepin but is not affected because it uses the logback framework for logging, not log4j 1.2.x Chainsaw.
  • ·In OpenShift Container Platform, the Hive/Presto/Hadoop Metering stack ships the vulnerable log4j package but the Chainsaw component is not used by default, reducing impact to Low.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.