Uploaded image for project: 'edge-rtac'
  1. edge-rtac
  2. EDGRTAC-26

Fix security vulnerability reported in log4j 1.2

    XMLWordPrintable

Details

    • Task
    • Status: Closed (View Workflow)
    • P2
    • Resolution: Done
    • None
    • 2.1.0
    • Gulfstream Sprint 94
    • 1
    • Gulfstream

    Description

      Remediation

      No patched version is available.

      Details

      CVE-2019-17571

      moderate severity

      *Vulnerable versions:* >= 1.2, <= 1.2.27

      *Patched version:* No fix

      Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                oyatsenko Oleksandr Yatsenko
                peter Peter Murray
                Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases