org.apache.logging.log4j/log4j-core

mavenframework

Overview

Canonical component data stored by Polaris.

Version

LATEST

Package Manager

maven

Type

framework

Systems

1

Licenses

No license information

Direct Dependencies

3

Technology

Not linked

External Signals
Maven Central endoflife.date OSV.dev
Package URL

pkg:maven/org.apache.logging.log4j/log4j-core@LATEST?type=jar

Maintenance

Derived from available component and registry data

Unknown
Maintenance health unknown
No component or registry publication date was available.
Confidence

Low

Version Age

—

Update Status

Unknown

Recent Activity

—

Reasons
Missing release dateUnsupported versionUpdate status unknown

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: Maven Central

Available
Ecosystem

maven

Latest Version

3.0.0-beta3

Published

—

Recent Releases

—

Advisories

—

Open Maven Central

Known Vulnerabilities

Source: OSV.dev

3 found

GHSA-7rjr-3q55-vv33

Incomplete fix for Apache Log4j vulnerability

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Versions
>= 2.13.0, before 2.16.0>= 2.4.0, before 2.12.2>= 1.8.0, before 1.9.2 +4 more
Open advisory

GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Affected Versions
>= 2.4.0, before 2.12.3>= 2.13.0, before 2.17.0all versions before 2.3.1 +4 more
Open advisory

GHSA-vwqq-5vrc-xw9h

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Versions
>= 2.13.0, before 2.13.2>= 2.4.0, before 2.12.3all versions before 2.3.2
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

3 direct dependencies

Global view