SCA: security update for log4j:log4j, org.apache.logging.log4j:log4j-core (GHSA-vp98-w2p3-mv35)

high Tenable Cloud Security Plugin ID 419448

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE
less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply
nested) hashmap or hashtable (depending on which logging component is in use) to be processed could
exhaust the available memory in the virtual machine and achieve Denial of Service when the object is
deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j
2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
(CVE-2023-26464)

See Also

https://github.com/advisories/GHSA-vp98-w2p3-mv35

Plugin Details

Severity: High

ID: 419448

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-26464

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/10/2023

Vulnerability Publication Date: 12/10/2021

Reference Information

CVE: CVE-2023-26464