Filtered by vendor Log4js Project
                         Subscriptions
                    
                    
                
                        Filtered by product Log4js
                         Subscriptions
                    
                    
                
                    Total
                    1 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2022-21704 | 2 Debian, Log4js Project | 2 Debian Linux, Log4js | 2025-04-23 | 5.5 Medium | 
| log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update. | ||||
                            
                                
                                
                                    Page 1 of 1.