Vulnerability record · CVE-2022-23307 · published 18 January 2022
CVE-2022-23307: Apache Chainsaw and Log4j 1.2.x Deserialization of Untrusted Data
Apache · Chainsaw
CVE-2022-23307 is a deserialization of untrusted data flaw (CWE-502) that was originally identified in Apache Chainsaw as CVE-2020-9493. The same issue exists in Apache Log4j 1.2.x, where Chainsaw was a component prior to Chainsaw V2.0, and it also affects the reload4j fork and multiple Oracle products that bundle these libraries.
Description
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and a 99th-percentile EPSS score indicate a serious, likely-exploitable deserialization flaw, though it is not in KEV and requires some privileges.
What it is
CVE-2022-23307 is a deserialization of untrusted data flaw (CWE-502) that was originally identified in Apache Chainsaw as CVE-2020-9493. The same issue exists in Apache Log4j 1.2.x, where Chainsaw was a component prior to Chainsaw V2.0, and it also affects the reload4j fork and multiple Oracle products that bundle these libraries.
Impact
An attacker who can supply crafted serialized data can trigger deserialization of untrusted input, leading to high impact on confidentiality, integrity and availability. Successful exploitation can result in remote code execution or full compromise of the affected process.
Attack surface
The CVSS vector AV:N/AC:L/PR:L/UI:N indicates the flaw is reachable over the network with low attack complexity, but requires the attacker to hold some level of privileges and no user interaction. The record does not specify the exact protocol or endpoint, so the precise entry point cannot be confirmed from the supplied data.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.54411 (99th percentile), indicating a meaningful probability of exploitation activity. Reference tags show only vendor advisories and Oracle patches, with no public exploit or PoC tags.
What to do
- Apply the Oracle CPU April 2022 and July 2022 patches for affected Oracle products.
- Upgrade Apache Chainsaw to V2.0 or later, where the deserialization issue is addressed.
- Migrate off Apache Log4j 1.2.x and reload4j to a maintained logging framework, or apply the vendor-recommended fix for the 1.2.x branch.
- Restrict network access to services that deserialize data so that only trusted, authenticated clients can reach them.
- Where deserialization cannot be avoided, enforce strict allow-list based object filtering on serialized input.
Detection
- Monitor application and server logs for deserialization errors, class-cast exceptions, or unexpected gadget-chain class loading.
- Alert on network connections to services that use Log4j 1.2.x or Chainsaw from untrusted or unusual source addresses.
- Use runtime instrumentation or EDR to detect suspicious object deserialization and subsequent process execution in Java workloads.
- Inventory hosts and applications still running Log4j 1.2.x, reload4j, or Chainsaw prior to V2.0 and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh | Mailing ListVendor Advisory |
| https://logging.apache.org/log4j/1.2/index.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | PatchThird Party Advisory |
| https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh | Mailing ListVendor Advisory |
| https://logging.apache.org/log4j/1.2/index.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | PatchThird Party Advisory |
Track CVE-2022-23307 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23307), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.