{"id":"CLSA-2022-1648067792","summary":"Fix of CVE: CVE-2021-4104, CVE-2022-23305, CVE-2022-23302, CVE-2022-23307","details":"- CVE-2022-23302: remove JMSSink component entrirely\n- CVE-2022-23305: ensure security of  JDBCAppender adding additional check-ups \n- CVE-2022-23307: restrict chainsaw access list to classes from SYSTEM_ALLOWED_CLASSES group\n- CVE-2021-4104: disable JMSAppender by default and add option to manually enable it","modified":"2026-06-01T00:33:20.176019673Z","published":"2022-03-23T20:36:32Z","upstream":["CVE-2021-4104","CVE-2022-23305","CVE-2022-23302","CVE-2022-23307"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/centos8.5-els/CLSA-2022-1648067792.html"}],"affected":[{"package":{"name":"log4j12","ecosystem":"TuxCare:CentOS:8.5","purl":"pkg:rpm/tuxcare/log4j12?distro=centos-8.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-24.module_el8.5.0+2018+25f04681.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2022-1648067792.json"}},{"package":{"name":"log4j12-javadoc","ecosystem":"TuxCare:CentOS:8.5","purl":"pkg:rpm/tuxcare/log4j12-javadoc?distro=centos-8.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-24.module_el8.5.0+2018+25f04681.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.5els/CLSA-2022-1648067792.json"}}],"schema_version":"1.7.5"}