[CLSA-2022:1644501061] Fix of CVE: CVE-2022-23302, CVE-2022-23307
Type:
security
Severity:
moderate
Release date:
2022-02-10
Description:
- CVE-2022-23307: Fix Unsafe deserialization flaw in Chainsaw log viewer - CVE-2022-23302: Fix remote code execution when application is configured to use JMSSink
Updated packages:
  • log4j-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:283dd7556888e2977556c49e5ee92c85cbf75600
  • log4j-javadoc-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:432340d8982fefa907e91b8baf5ce373019b2dd2
  • log4j-manual-1.2.14-6.4.el6.tuxcare.els3.x86_64.rpm
    sha:7994110a98ff6ceb5d6bfa3cb4f73295f25952cb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.