Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYFRAMEWORKPARTIAL

Apache

Apache Log4j

Apache Log4j is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Apache Log4j is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

Lifecycle records

ReleaseBoundaryDate
Lifecycle policyOfficial lifecycle policy; no bounded date foundNot dated by publisher

Official sources

PARTIAL

Apache Log4j official lifecycle source

Checked automatically.

Extracted 1 lifecycle record(s), including 0 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Incomplete fix for Apache Log4j vulnerability

Fixed: 2.16.0, 2.12.2

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

Fixed: 2.12.3, 2.17.0, 2.3.1

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Fixed: 2.25.4

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

Fixed: 2.25.4

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Fixed: 2.25.4

Apache Log4j does not verify the TLS hostname in its Socket Appender

Fixed: 2.25.3

Improper Input Validation and Injection in Apache Log4j2

Fixed: 2.3.2, 2.12.4, 2.17.1

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

Fixed: 2.13.2, 2.12.3, 2.3.2