CVE-2022-23307

Updated: 2025-08-20 01:45:02.595368

Description:

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x HIGH 9.0
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 6 ELS log4j 1.2.14 8.8 HIGH Released CLSA-2022:1644501061 2022-04-19 21:49:52
CentOS 6 ELS log4j 1.2.14 8.8 HIGH Released CLSA-2022:1644500972 2022-05-05 12:04:34
CloudLinux 6 ELS log4j 1.2.14 8.8 HIGH Released CLSA-2022:1644583038 2022-04-19 21:49:52
CentOS 7 ELS log4j 1.2.17 8.8 HIGH Already Fixed 2025-07-11 01:40:25
CentOS 8.5 ELS log4j12 1.2.17-24 8.8 HIGH Released CLSA-2022:1648067792 2022-04-19 21:49:52
CentOS 8.4 ELS log4j12 1.2.17-24 8.8 HIGH Released CLSA-2022:1648069165 2022-04-19 21:49:52