CVE record
CVE-2021-44228
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
critical
CVSS 10.0 ยท CVSS_V3
Affected packages
5
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Apache
- Product
- Log4j2
- Date added
- Dec 10, 2021
- CISA federal remediation due date
- Dec 24, 2021
- Required action
- For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
- Known ransomware campaign use
- Known
- CWE
- CWE-20, CWE-400, CWE-502
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| org.apache.logging.log4j:log4j-core | maven | 2.15.0, 2.3.1, 2.12.2 |
| com.guicedee.services:log4j-core | maven | Not specified |
| org.xbib.elasticsearch:log4j | maven | Not specified |
| uk.co.nichesolutions.logging.log4j:log4j-core | maven | Not specified |
| org.ops4j.pax.logging:pax-logging-log4j2 | maven | 1.9.2, 1.10.8, 1.11.10, 2.0.11 |