It was discovered that Apache Log4j does not properly deserialize untrusted data. An attacker could possibly use this issue to remotely execute arbitrary code. (CVE-2019-17571)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.2.17-8+deb10u1build0.18.04.1", "binary_name": "liblog4j1.2-java" }, { "binary_version": "1.2.17-8+deb10u1build0.18.04.1", "binary_name": "liblog4j1.2-java-doc" } ] }