org.apache.logging.log4j/log4j-core
mavenframework
Overview
Canonical component data stored by Polaris.
Version
LATEST
Package Manager
maven
Type
framework
Systems
1
Licenses
No license information
Direct Dependencies
3
Technology
Not linked
External Signals
Maven Central endoflife.date OSV.dev
Package URL
pkg:maven/org.apache.logging.log4j/log4j-core@LATEST?type=jar
Maintenance
Derived from available component and registry data
Maintenance health unknown
No component or registry publication date was available.
Confidence
Low
Version Age
—
Update Status
Unknown
Recent Activity
—
Reasons
Missing release dateUnsupported versionUpdate status unknown
Lifecycle
Source: endoflife.date
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Registry
Source: Maven Central
Ecosystem
maven
Latest Version
3.0.0-beta3
Published
—
Recent Releases
—
Advisories
—
Known Vulnerabilities
Source: OSV.dev
GHSA-7rjr-3q55-vv33
Incomplete fix for Apache Log4j vulnerability
Affected Versions
Open advisory>= 2.13.0, before 2.16.0all versions before 2.12.2>= 1.8.0, before 1.9.2 +3 more
GHSA-p6xc-xr62-6r2g
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Affected Versions
Open advisory>= 2.4.0, before 2.12.3>= 2.13.0, before 2.17.0all versions before 2.3.1 +4 more
GHSA-vwqq-5vrc-xw9h
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
Affected Versions
Open advisory>= 2.13.0, before 2.13.2>= 2.4.0, before 2.12.3all versions before 2.3.2
Security
Source: OpenSSF Scorecard
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.
Systems (1)
Dependencies
3 direct dependencies