ThreatCluster

Apache Log4j Vulnerability Exposes Sensitive Log Data to Attackers

First seen 19 Dec 2025, 18:59 UTC GbhackersCyberpressCybersecuritynews 95% similarity 45

Article Content

Browse articles
ThreatCluster

Apache Logging Services has disclosed a critical vulnerability in Log4j Core that allows attackers to intercept sensitive log data. This flaw affects versions 2.0-beta9 through 2.25.2, specifically in the Socket Appender component, which fails to verify TLS, enabling potential man-in-the-middle attacks. Users of the affected versions are urged to update to secure their applications.

ThreatCluster AI

Community

Browse all →