Log4js Project maintains a lightweight logging library for Node.js applications, with a vulnerability footprint centered on its single core product and characterized by configuration and permission-handling issues such as improper default permissions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Log4js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21704MEDIUM log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in | Jan 19, 2022 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Log4js Project.
Media articles that mention a CVE ID that affects a product developed by Log4js Project — matched by CVE ID, not by vendor name.