{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Deserialization Vulnerability",
    "tracking": {
      "current_release_date": "2026-08-11T17:01:28+00:00",
      "generator": {
        "date": "2026-08-11T17:01:28+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2023-34050",
      "initial_release_date": "2023-10-19T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T17:01:28+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.9",
            "product": {
              "name": "Red Hat Enterprise Linux 9.9",
              "product_id": "rhel-9",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j",
            "product": {
              "name": "log4j",
              "product_id": "log4j",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j-jcl",
            "product": {
              "name": "log4j-jcl",
              "product_id": "log4j-jcl",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j-jcl"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j-slf4j",
            "product": {
              "name": "log4j-slf4j",
              "product_id": "log4j-slf4j",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j-slf4j"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j",
            "product": {
              "name": "log4j",
              "product_id": "log4j.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:log4j"
        },
        "product_reference": "log4j",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-jcl as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:log4j-jcl"
        },
        "product_reference": "log4j-jcl",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-slf4j as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:log4j-slf4j"
        },
        "product_reference": "log4j-slf4j",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j.src as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:log4j.src"
        },
        "product_reference": "log4j.src",
        "relates_to_product_reference": "rhel-9"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-34050",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "discovery_date": "2023-10-25T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-9:log4j",
            "rhel-9:log4j-jcl",
            "rhel-9:log4j-slf4j",
            "rhel-9:log4j.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "This flaw requires previous knowledge and access to the messages in order to get them deserialized and possibly leak information. It also requires missing server side configurations to prevent unwanted behavior. Therefore, this is rated as a Moderate impact.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in Spring Framework AMQP. An allowed list exists in Spring AMQP, but when no allowed list is provided, all classes could be deserialized, allowing a malicious user to send harmful content to the broker.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhel-9:log4j",
          "rhel-9:log4j-jcl",
          "rhel-9:log4j-slf4j",
          "rhel-9:log4j.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-34050"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34050"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-34050"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhel-9:log4j",
            "rhel-9:log4j-jcl",
            "rhel-9:log4j-slf4j",
            "rhel-9:log4j.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhel-9:log4j",
            "rhel-9:log4j-jcl",
            "rhel-9:log4j-slf4j",
            "rhel-9:log4j.src"
          ]
        }
      ],
      "title": "Deserialization Vulnerability"
    }
  ]
}