An open index of dependabot pull requests across open source projects.

org.apache.logging.log4j:log4j-core

Ecosystem:
maven
Package URL:
pkg:maven/org.apache.logging.log4j:log4j-core
Total PRs:
1,117 Dependabot PRs
Latest PR:
17 days ago
Unique Repositories:
559 repositories
Unique Repos (30 days):
4 repositories
Security Advisories
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
GHSA-vwqq-5vrc-xw9h CVE-2020-9488 LOW published about 6 years ago • updated about 14 hours ago
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender prior to version 2.13.2. This could allow an SMTPS connection t...
Remote code injection in Log4j
GHSA-jfh8-c2jp-5v3q CVE-2021-44228 CRITICAL published over 4 years ago • updated about 7 hours ago
# Summary Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser. As per [Apache's Log4j sec...
Improper Input Validation and Injection in Apache Log4j2
GHSA-8489-44mv-ggj8 CVE-2021-44832 MODERATE published over 4 years ago • updated about 2 hours ago
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker wi...
Incomplete fix for Apache Log4j vulnerability
GHSA-7rjr-3q55-vv33 CVE-2021-45046 CRITICAL published over 4 years ago • updated about 8 hours ago
# Impact The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non...
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
GHSA-p6xc-xr62-6r2g CVE-2021-45105 HIGH published over 4 years ago • updated about 7 hours ago
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This...
Recent PRs
Package Details
Name: org.apache.logging.log4j:log4j-core
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/org.apache.logging.log4j:log4j-core
JSON API: View JSON
Security Advisories

10

Active advisories
CRITICAL 2
HIGH 2
MODERATE 5
LOW 1
View All maven Advisories
Package Information
Description:

The Apache Log4j Implementation

Repository: https://github.com/apache/logging-log4j2
Homepage: https://logging.apache.org/log4j/3.x/
Latest Release: 2.24.3
over 1 year ago
Dependent Repos: 82,953
Dependent Packages: 8,839
Ranking: Top 0.0126% by dependent repos Top 0.0068% by dependent pkgs
PR Status
Open 535 (47.9%)
Merged 214 (19.2%)
Closed 362 (32.4%)
PR Types
Major 1 (0.1%)
Minor 632 (56.6%)
Patch 449 (40.2%)