Apple and Apache Log4j 1.x Chainsaw Vulnerabilities
Over the past week, a deserialization vulnerability in the Apache Log4j 1.x Chainsaw component was disclosed. Moreover, Apple fixed zero-day vulnerabilities, one of which is exploited in the wild and could lead to an information leak. In addition, security researchers discovered that two vulnerabilities in Control Web Panel (CWP) - when chained together - can lead to Remote Code Execution (RCE), as root on vulnerable Linux servers. Even though one of the vulnerabilities was patched, some have managed to reverse the patch and exploit vulnerable servers. Another vulnerability in Linux that impacts the Linux kernel was discovered this week.





