{"id":"CLSA-2022-1648069165","summary":"Fix of CVE: CVE-2022-23307, CVE-2021-4104, CVE-2022-23305, CVE-2022-23302","details":"- CVE-2022-23302: remove JMSSink component entrirely\n- CVE-2022-23305: ensure security of  JDBCAppender adding additional check-ups \n- CVE-2022-23307: restrict chainsaw access list to classes from SYSTEM_ALLOWED_CLASSES group\n- CVE-2021-4104: disable JMSAppender by default and add option to manually enable it","modified":"2026-06-01T00:33:19.143004484Z","published":"2022-03-23T20:59:25Z","upstream":["CVE-2022-23307","CVE-2021-4104","CVE-2022-23305","CVE-2022-23302"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/centos8.4-els/CLSA-2022-1648069165.html"}],"affected":[{"package":{"name":"log4j12","ecosystem":"TuxCare:CentOS:8.4","purl":"pkg:rpm/tuxcare/log4j12?distro=centos-8.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-24.module_el8.4.0+2019+25f04681.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1648069165.json"}},{"package":{"name":"log4j12-javadoc","ecosystem":"TuxCare:CentOS:8.4","purl":"pkg:rpm/tuxcare/log4j12-javadoc?distro=centos-8.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-24.module_el8.4.0+2019+25f04681.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1648069165.json"}}],"schema_version":"1.7.5"}