elsa-2022-0442
oracle_linux
Description
[0:1.2.17-18] - Fix Unsafe deserialization flaw in Chainsaw log viewer - Fix SQL injection when application is configured to use JDBCAppender - Fix remote code execution when application is configured to use JMSSink - Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-23302
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2022-23302",
"CVE-2022-23305",
"CVE-2022-23307"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[0:1.2.17-18]\n- Fix Unsafe deserialization flaw in Chainsaw log viewer\n- Fix SQL injection when application is configured to use JDBCAppender\n- Fix remote code execution when application is configured to use JMSSink\n- Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-23302",
"id": "ELSA-2022-0442",
"ovalId": "oval:com.oracle.elsa:def:20220442",
"source": "oracle_linux",
"title": "ELSA-2022-0442: log4j security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2022-0442.html"
}