Back to overview

CVE-2021-44228

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Metadata

CVE ID
CVE-2021-44228
State
PUBLISHED
Assigner
apache
Reserved
2021-11-26 00:00 UTC
Published
2021-12-10 00:00 UTC
Last updated
2025-10-21 23:25 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
Apache Software Foundation / Apache Log4j2
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Apache Log4j2 Remote Code Execution Vulnerability
Vendor
Apache
Product
Log4j2
Added to KEV
2021-12-10
Due date
2021-12-24
Ransomware
Known use
Required action
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
CISA description
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Apache Log4j2 2.0-beta9 < log4j-core*
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper Input Validation
CWE-400 cna CWE-400 Uncontrolled Resource Consumption
CWE-502 cna CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References (53)
Back to overview