ppkarwasz opened a new pull request, #43: URL: https://github.com/apache/logging-site/pull/43
The security FAQ claimed that the `SocketServer` receiver was never reintroduced into the Log4j 2 production codebase. This is inaccurate: `log4j-core` contained TCP and UDP socket servers inherited from Log4j 1 up to and including the 2.8.x releases. As any endpoint consuming serialized data, they were dangerous to use and resulted in CVE-2017-5645. The vulnerability was patched in 2.8.2 by introducing `FilteredObjectInputStream` as a Java 7 equivalent of the `ObjectInputFilter` API introduced in Java 9, but since the fix could not cover all cases the socket servers were removed in 2.9.0. This change corrects the section and expands it with this history, cross-linking the CVE-2017-5645 entry on the security page. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01GeV6uBXR77uZVnPAUUjF6n -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
