Apache Log4j Vulnerability Allow Attackers to Intercept Sensitive Log Data
Apache Logging Services has identified a critical security vulnerability in Log4j Core, potentially exposing applications to the interception of log data.
Apache Logging Services has identified a critical security vulnerability in Log4j Core, potentially exposing applications to the interception of log data.
This vulnerability is found in the Socket Appender component and affects versions 2.0-beta9 through 2.25.2. It presents a man-in-the-middle attack vector due to inadequate TLS hostname verification in peer certificates.
Attackers can intercept or redirect sensitive logging traffic if positioned between a client and a log receiver. This vulnerability requires specific conditions to exploit, including the presentation of a server certificate from a trusted certification authority.
CVE ID Component Affected Versions CVSS Score Issue
CVE-2025-68161 Apache Log4j Core 2.0-beta9 through 2.25.2 6.3 Missing TLS hostname verification in Socket Appender
Apache Logging Services has identified a critical security vulnerability in Log4j Core, potentially exposing applications to the interception of log data.
Logging frameworks inherently manage sensitive data, including user activities and system events. This vulnerability undermines data protection, allowing unauthorized access to log streams.
Apache has released version 2.25.3 of Log4j Core to address this TLS hostname verification issue. Organizations using affected versions should upgrade immediately to secure their logging infrastructure.
For systems unable to upgrade, it is recommended to carefully restrict the use of trust stores by configuring them to include only necessary CA certificates, following NIST SP 800-52 Rev. 2 guidelines.
The Apache Logging Services Security Team maintains a security vulnerability disclosure program to ensure accurate and comprehensive security information. Organizations are advised to review their Log4j versions and implement updates promptly.
The team continues to monitor dependencies and address security threats affecting its logging solutions used across global enterprise applications.
Based on reporting by Cyber Security News.
