{"api_version":"v1","generated_at":"2026-10-06T22:50:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-log4j-58c9e774f119","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Log4j","next_cursor":null,"observations":[{"affected":"1.0.4 < 2","affected_versions_present":true,"cve_id":"CVE-2023-26464","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-26464","fixed":"2 \u2264 *","last_modified":"2025-02-13T16:44:55.555Z","patch_url":"https://lists.apache.org/thread/wkx6grrcjkh86crr49p4blc1v1nflj3t","primary_source":"","published":"2023-03-10T13:38:16.190Z"},{"affected":"All versions between 2.0-alpha1 and 2.8.1","affected_versions_present":true,"cve_id":"CVE-2017-5645","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5645","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T15:11:47.391Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2017-04-17T21:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
