Ecosyste.ms: Packages

An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 0.1% on repo1.maven.org
Top 0.1% dependent packages on repo1.maven.org
Top 0.1% dependent repos on repo1.maven.org
Top 0.1% docker downloads on repo1.maven.org

repo1.maven.org : log4j:log4j

Apache Log4j 1.2

Registry - Source - Homepage - Documentation - JSON
purl: pkg:maven/log4j/log4j
License: Apache-2.0
Latest release: almost 12 years ago
First release: over 18 years ago
Namespace: log4j
Dependent packages: 13,845
Dependent repositories: 236,580
Docker dependents: 6,402
Docker downloads: 1,501,275,855
Last synced: about 10 hours ago

High
GSA_kwCzR0hTQS13OXAzLTVjcjgtbTNqas0kWg
Deserialization of Untrusted Data in Log4j 1.x
Ecosystems: maven
Packages: org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Source: github
Published: over 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJxcmcteDIyOS0zdjhx
Deserialization of Untrusted Data in Log4j
Ecosystems: maven
Packages: org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Source: github
Published: over 4 years ago
Critical
GSA_kwCzR0hTQS1mN3ZoLXF3cDMteDM3bc0kWQ
Deserialization of Untrusted Data in Apache Log4j
Ecosystems: maven
Packages: org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Source: github
Published: over 2 years ago
Critical
GSA_kwCzR0hTQS02NWZnLTg0ZjYtM2pxM80kaQ
SQL Injection in Log4j 1.2.x
Ecosystems: maven
Packages: org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Source: github
Published: over 2 years ago
High
GSA_kwCzR0hTQS1mcDVyLXYzdzktNDMzM80bRA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
Ecosystems: maven
Packages: org.zenframework.z8.dependencies.commons:log4j-1.2.17, log4j:log4j
Source: github
Published: over 2 years ago