CVE-2022-23307 - CVE House
Back to Database
Status published Unknown CVE-2022-23307

A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.

Vulnerability Description

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23307

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • @kingkk

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Log4j 1.x
Vulnerable Versions:
1.2.1, unspecified

Timeline

Official Publish: January 18th, 2022
Last Modified: May 27th, 2026
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)