{"id":"DSA-4686-1","summary":"apache-log4j1.2 - security update","modified":"2026-03-09T02:09:35.685439Z","published":"2020-05-16T00:00:00Z","upstream":["CVE-2019-17571","DEBIAN-CVE-2019-17571"],"affected":[{"package":{"name":"apache-log4j1.2","ecosystem":"Debian:9","purl":"pkg:deb/debian/apache-log4j1.2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-7+deb9u1"}]}],"versions":["1.2.17-7"],"database_specific":{"source":"https://storage.googleapis.com/debian-osv/dsa-osv/DSA-4686-1.json"}},{"package":{"name":"apache-log4j1.2","ecosystem":"Debian:10","purl":"pkg:deb/debian/apache-log4j1.2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-8+deb10u1"}]}],"versions":["1.2.17-8"],"database_specific":{"source":"https://storage.googleapis.com/debian-osv/dsa-osv/DSA-4686-1.json"}}],"schema_version":"1.7.3"}