Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17. Users are advised to migrate to `org.apache.logging.log4j:log4j-core`.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanDeserialization of Untrusted Data in Log4j affects log4j:log4j (maven), org.zenframework.z8.dependencies.commons:log4j-1.2.17 (maven). Severity is critical. Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17. Users are advised to migrate to `org.apache.logging.log4j:log4j-core`.
AI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| log4j:log4jmaven | >=1.2,<=1.2.17 | Not reported |
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17. Users are advised to migrate to `org.apache.logging.log4j:log4j-core`.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanDeserialization of Untrusted Data in Log4j affects log4j:log4j (maven), org.zenframework.z8.dependencies.commons:log4j-1.2.17 (maven). Severity is critical. Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17. Users are advised to migrate to `org.apache.logging.log4j:log4j-core`.
AI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| log4j:log4jmaven | >=1.2,<=1.2.17 | Not reported |
| org.zenframework.z8.dependencies.commons:log4j-1.2.17maven |
|---|
| =2.0 |
| Not reported |
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.zenframework.z8.dependencies.commons:log4j-1.2.17maven |
|---|
| =2.0 |
| Not reported |
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard