{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos6els/vex/2020/cve-2020-9493-els_os-centos6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-12T15:53:45Z",
      "generator": {
        "date": "2026-06-12T15:53:45Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2020-9493-ELS_OS-CENTOS6ELS",
      "initial_release_date": "2020-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2020-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2025-10-16T13:22:03Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2025-12-23T20:26:03Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-06-12T15:53:45Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2020-9493"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 6",
                "product": {
                  "name": "Community Enterprise Operating System 6",
                  "product_id": "CentOS-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                "product": {
                  "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_id": "log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/log4j@1.2.14-6.4.el6.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                "product": {
                  "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_id": "log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/log4j@1.2.14-6.4.el6.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_id": "log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/log4j@1.2.14-6.4.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                "product": {
                  "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_id": "log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/log4j@1.2.14-6.4.el6.tuxcare.els4?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                "product": {
                  "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_id": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-manual@1.2.14-6.4.el6.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                "product": {
                  "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_id": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-manual@1.2.14-6.4.el6.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_id": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-manual@1.2.14-6.4.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                "product": {
                  "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_id": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-manual@1.2.14-6.4.el6.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_id": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-javadoc@1.2.14-6.4.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                "product": {
                  "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_id": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-javadoc@1.2.14-6.4.el6.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                "product": {
                  "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_id": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-javadoc@1.2.14-6.4.el6.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                "product": {
                  "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_id": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/log4j-javadoc@1.2.14-6.4.el6.tuxcare.els4?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64"
        },
        "product_reference": "log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64"
        },
        "product_reference": "log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
        },
        "product_reference": "log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64"
        },
        "product_reference": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
        },
        "product_reference": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64"
        },
        "product_reference": "log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64"
        },
        "product_reference": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64"
        },
        "product_reference": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
        },
        "product_reference": "log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
        "relates_to_product_reference": "CentOS-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-9493",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "notes": [
        {
          "category": "description",
          "text": "A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
          "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
          "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
          "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
          "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
          "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
          "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
          "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
          "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
          "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
          "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
          "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2020-9493"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2021/06/16/1",
          "url": "http://www.openwall.com/lists/oss-security/2021/06/16/1"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2022/01/18/5",
          "url": "http://www.openwall.com/lists/oss-security/2022/01/18/5"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/r50d389c613ba6062a26aa57e163c09bfee4ff2d95d67331d75265b83%40%3Cannounce.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/r50d389c613ba6062a26aa57e163c09bfee4ff2d95d67331d75265b83%40%3Cannounce.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://www.openwall.com/lists/oss-security/2021/06/16/1",
          "url": "https://www.openwall.com/lists/oss-security/2021/06/16/1"
        }
      ],
      "release_date": "2021-06-16T08:15:00Z",
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        },
        {
          "category": "impact",
          "date": "2026-06-12T12:58:45.342304Z",
          "details": "Not vulnerable: CVE-2020-9493 applies to Apache Chainsaw (a standalone log viewer) and requires Chainsaw ≤2.0/2.1.0 to deserialize untrusted network input; it does not target the Log4j 1.2.14 library itself. For Log4j 1.x, the analogous issue is tracked as CVE-2022-23307, which has already been remediated, removing the vulnerable Chainsaw/receiver code path. Major Linux vendor trackers also classify CVE-2020-9493 as not applicable to their packaged software, reinforcing that this environment is unaffected.",
          "product_ids": [
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-javadoc-0:1.2.14-6.4.el6.tuxcare.els4.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els1.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els2.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els3.x86_64",
            "CentOS-6:log4j-manual-0:1.2.14-6.4.el6.tuxcare.els4.x86_64"
          ]
        }
      ]
    }
  ]
}