#CVE-2021-44228

Vulnerability/Target

2021-12-11 • Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation

Apache Log4j2 log4j-core versions 2.0-beta9 through 2.15.0, excluding security releases 2.12.2, 2.12.3, and 2.3.1, fail to protect JNDI features from attacker-controlled LDAP and other JNDI endpoints. An attacker who controls log messages or their parameters can execute arbitrary code loaded from an LDAP server when message lookup substitution is enabled; the behavior was disabled by default in 2.15.0 and removed in 2.16.0, 2.12.2, 2.12.3, and 2.3.1. Other Apache Logging Services projects such as log4net and log4cxx are not affected.

https://www.cve.org/CVERecord?id=CVE-2021-44228

Tagged Reports

« Back