{"id":"GHSA-xxfh-x98p-j8fr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xxfh-x98p-j8fr","summary":"Remote code injection in Log4j (through pax-logging-log4j2)","details":"### Impact\nRemote Code Execution.\n\n### Patches\nUsers of pax-logging 1.11.9 should update to 1.11.10.\nUsers of pax-logging 2.0.10 should update to 2.0.11.\n\n### Workarounds\nSet system property `-Dlog4j2.formatMsgNoLookups=true`\n\n### References\nhttps://github.com/advisories/GHSA-jfh8-c2jp-5v3q\n\n","published":"2021-12-10T20:15:37Z","modified":"2024-12-02T05:49:25.675395Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"2.0.11"},{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"1.11.10"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ops4j/org.ops4j.pax.logging/security/advisories/GHSA-xxfh-x98p-j8fr"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jfh8-c2jp-5v3q"},{"type":"PACKAGE","url":"https://github.com/ops4j/org.ops4j.pax.logging"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:49:25.675395Z"}}