Loading
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Use CWE-502, Apache vendor hub and Log4j product page to widen CVE-2017-5645 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-45046, CVE-2022-23305 and CVE-2022-23307 for nearby disclosures in the same product family.