Back

CRITICAL

A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.

Published Jan 18, 2022

Description

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Affected products

Remediation

Vendor solution

Upgrade to Apache Log4j 2 and Apache Chainsaw 2.1.0.

Red Hat statement

Chainsaw is a standalone graphical user interface for viewing log entries in log4j. This flaw may be bypassed by using other available means to access log entries. Red Hat Satellite bundles log4j-over-slf4j with Candlepin, however, product is not affected as it uses logback framework for logging. Red Hat Virtualization ships a vulnerable version of the log4j package, however chainsaw is not part of typical use cases. An attacker looking to exploit this would need to not only be able to generate a malicious log entry, but also have the necessary access and permissions to start chainsaw on the engine node. Therefore the impact of this vulnerability for Red Hat Virtualization is rated Low. Similar to Red Hat Virtualization in OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of log4j package, however vulnerable chainsaw component is not used by default. Therefore the impact to OCP is reduced to Low.

Red Hat mitigation

These are the mitigations available for this flaw for log4j 1.x: - Avoid using Chainsaw to view logs, and instead use some other utility, especially if there is a log view available within the product itself. - Remove the Chainsaw classes from the log4j jar files. For example: ``` zip -q -d log4j-*.jar org/apache/log4j/chainsaw/* ``` (log4j jars may be nested in zip archives within product)

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 18, 2022
Updated May 27, 2026
Reserved Jan 17, 2022
CISA Vulnrichment
Updated May 22, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 18, 2022
GHSA-F7VH-QWP3-X37M