Apache Log4cxx
cpe:2.3:a:apache:log4cxx:*:*:*:*:*:*:*
- >= 0.11.0, < 1.5.0
A vulnerability exists in Apache Log4cxx versions prior to 1.5.0, specifically within the JSONLayout component. The issue arises because certain non-printable characters in attacker-supplied messages are not properly escaped. As a result, these characters can be included in the JSON output, potentially leading to misinterpretation of the log data by applications that process these logs.
This vulnerability can cause log injection, a common attack vector that obscures malicious activity within an application. By exploiting this issue, an attacker could manipulate log messages in a way that disrupts the intended structure and clarity of the JSON data, making it difficult for log-consuming applications to accurately interpret the information.
Users are advised to upgrade to Apache Log4cxx version 1.5.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.