CVE-2017-5645
CRITICAL NUCLEIApache Log4j 2.0-2.8.1 - Remote Code Execution via Untrusted Data Deserialization
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2017-5645. PoCs published by pimps, HynekPetrak, The-Real-TechLord. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains only a README file describing CVE-2017-5645, an Apache Log4j RCE vulnerability due to insecure deserialization. No actual exploit code or proof-of-concept is present.
Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Exploits (3)
This repository contains only a README file describing CVE-2017-5645, an Apache Log4j RCE vulnerability due to insecure deserialization. No actual exploit code or proof-of-concept is present.
This repository contains a Python-based file system scanner for detecting vulnerable log4j instances, including CVE-2017-5645. It identifies log4j (1.x), reload4j (1.2.18+), and log4j-core (2.x) versions vulnerable to multiple CVEs.
The repository contains only a minimal README with a CVE title and description, lacking any exploit code, technical details, or proof-of-concept implementation.
Nuclei Templates (1)
References (82)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H