cbcvebase.
CVE-2023-26464
published 2023-03-10

CVE-2023-26464: ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a…

PriorityP275high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.91%
77.4th percentile
** UNSUPPORTED WHEN ASSIGNED **

When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested)
hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.

This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachelog4j>= 1.0.4 < 2.02.0
apache_software_foundationapache_log4j>= 1.0.4 < 22
debianapache-log4j1.2

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable components are Chainsaw and SocketAppender in Log4j 1.x; detection should focus on use of these components with JRE < 1.7 processing deserialized objects
  • Attack vector is network/HTTP; monitor for unexpected large or deeply nested serialized hashmap/hashtable objects sent to Log4j 1.x SocketAppender listener ports
  • Red Hat identifies the vulnerable package as log4j1-socketappender; inventory and alert on deployments of log4j (version 1.x) where SocketAppender or Chainsaw is enabled
  • ·Vulnerability only affects Log4j 1.x (before version 2) running on JRE less than 1.7; Log4j 2.x is not affected
  • ·Red Hat Enterprise Linux 8 and 9 are rated Low severity because they do not enable the vulnerable JDK by default
  • ·This is an unsupported/EOL product; the maintainer will not issue a patch for Log4j 1.x
  • ·No mitigation meeting Red Hat's criteria is currently available for affected products

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_oracle6.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.