logo

Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data

ID: 26484383-707b-5b70-806a-bb077cbe21bd

STIX ID: report--26484383-707b-5b70-806a-bb077cbe21bd

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

Apache Logging Services disclosed CVE-2025-68161: a missing TLS hostname verification in Log4j Core's Socket Appender (affecting 2.0-beta9 through 2.25.2) that can allow a man-in-the-middle with a trusted certificate to intercept or redirect sensitive logging traffic; Apache released Log4j 2.25.3 to fix the issue and recommends restricting trust stores as a mitigation for systems that cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.