org.apache.logging.log4j/log4j-core

mavenframework

Overview

Canonical component data stored by Polaris.

Version

LATEST

Package Manager

maven

Type

framework

Systems

1

Licenses

No license information

Direct Dependencies

3

Technology

Not linked

External Signals
Maven Central endoflife.date OSV.dev
Package URL

pkg:maven/org.apache.logging.log4j/log4j-core@LATEST?type=jar

Maintenance

Derived from available component and registry data

Unknown
Maintenance health unknown
No component or registry publication date was available.
Confidence

Low

Version Age

Update Status

Unknown

Recent Activity

Reasons
Missing release dateUnsupported versionUpdate status unknown

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: Maven Central

Available
Ecosystem

maven

Latest Version

3.0.0-beta3

Published

Recent Releases

Advisories

Open Maven Central

Known Vulnerabilities

Source: OSV.dev

3 found

GHSA-7rjr-3q55-vv33

Incomplete fix for Apache Log4j vulnerability

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H
Affected Versions
>= 2.13.0, before 2.16.0all versions before 2.12.2>= 1.8.0, before 1.9.2 +3 more
Open advisory

GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Affected Versions
>= 2.4.0, before 2.12.3>= 2.13.0, before 2.17.0all versions before 2.3.1 +4 more
Open advisory

GHSA-vwqq-5vrc-xw9h

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Versions
>= 2.13.0, before 2.13.2>= 2.4.0, before 2.12.3all versions before 2.3.2
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

3 direct dependencies

Global view