CVE-2024-23049: b3log Symphony

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

Affected products

  • b3log Symphony: up to and including 3.6.3

Published 2024-02-05. Last modified 2026-06-17.