[CLSA-2022:1644500972] Fixed CVEs in log4j: CVE-2022-23302, CVE-2022-23307
Type:
security
Severity:
Important
Release date:
2022-02-10
Description:
- CVE-2022-23307: Fix Unsafe deserialization flaw in Chainsaw log viewer - CVE-2022-23302: Fix remote code execution when application is configured to use JMSSink
Updated packages:
  • log4j-manual-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:0550ade6da97ee3fa2841fef86e2dd49ae139239
  • log4j-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:4519b1ffed51fd76f4c6c4e524fb005fa124fe2c
  • log4j-javadoc-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:d622b6d6b557c51ad198336cb290af7e18a4d3e2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.