Skip to content

Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data

Cybersecuritynews Abinaya December 19, 2025

Apache Logging Services has disclosed a critical security vulnerability in Log4j Core that exposes applications to potential interception of log data. The flaw resides in the Socket Appender component. It affects versions 2.0-beta9 through 2.25.2, creating a man-in-the-middle attack vector for malicious actors. The Socket Appender in affected Log4j versions fails to verify the TLS […]

Extracted Entities

Attack Types (1)