Vulnerability record · CVE-2022-23302 · published 18 January 2022
CVE-2022-23302: Apache Log4j 1.x JMSSink JNDI deserialization remote code execution
Apache · Log4j
JMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration references an attacker-controlled LDAP service. A crafted TopicConnectionFactoryBindingName value causes JMSSink to issue JNDI requests that can lead to remote code execution, similar to CVE-2021-4104. The issue only affects Log4j 1.x when JMSSink is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015.
Description
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and a very high EPSS percentile indicate significant risk, but exploitation requires non-default JMSSink configuration and low-privileged access to configuration or LDAP, and the flaw is not in CISA KEV.
What it is
JMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration references an attacker-controlled LDAP service. A crafted TopicConnectionFactoryBindingName value causes JMSSink to issue JNDI requests that can lead to remote code execution, similar to CVE-2021-4104. The issue only affects Log4j 1.x when JMSSink is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015.
Impact
An attacker who can influence the Log4j configuration or an LDAP service it references can execute arbitrary code in the context of the affected application. CVSS 3.1 scores this 8.8 (High) with high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N), but it requires low privileges (PR:L) because the attacker must have write access to the Log4j configuration or control of a referenced LDAP service. It is not exploitable in default configurations; JMSSink must be specifically enabled.
Exploitation
CVE-2022-23302 is not listed in CISA KEV and has no documented ransomware use, but EPSS is high at 0.63556 (99.175th percentile), indicating elevated predicted exploitation activity. References include vendor advisories and Oracle patch notices, but no public exploit code is cited in the record.
What to do
- Upgrade from Log4j 1.x to Log4j 2, which is the vendor-recommended fix and addresses this and other issues.
- If upgrade is not immediately possible, remove or disable JMSSink usage and avoid referencing untrusted LDAP services in Log4j configuration.
- Restrict write access to Log4j configuration files to trusted administrators only.
- Apply vendor patches for affected products (for example Oracle CPU April/July 2022 advisories) where Log4j 1.x is bundled.
- Monitor and block outbound JNDI/LDAP connections from application servers that do not require them.
Detection
- Search application and server logs for JMSSink initialization and JNDI/LDAP lookups originating from Log4j 1.x components.
- Monitor file integrity on Log4j configuration files for unauthorized changes, especially TopicConnectionFactoryBindingName entries.
- Detect outbound LDAP or JNDI traffic from Java application servers to unexpected or external hosts.
- Inventory applications and dependencies for Log4j 1.x and flag any that use JMSSink.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23302 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23302), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.