SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) https://lists.apache.org/thread/vgjlpdf353vv91gryspwxrzj6p0fbjd9
Created log4cxx tracking bugs for this issue: Affects: epel-8 [bug 2196728] Affects: fedora-all [bug 2196729]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-31038