openSUSE Tumbleweed — log4j12 — multiple vulnerabilities (4 CVEs) — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory openSUSE-SU-2022:0038-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23305 CVE-2022-23307 CVE-2022-23302 CVE-2017-5645 Upstream summary: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to […]