CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

  • OS
    Any OS
  • Version
    Any Version
  • Type
    Any Type

13 fixes found:

    Workaround

    Log4HotPatch by Correto
    Published Date:Dec 12, 2021
    Updated Date:Dec 12, 2021

      Workaround

      Apache Log4j Security Update - Log4j
      Published Date:Dec 10, 2021
      Updated Date:Dec 10, 2021

        Workaround

        Apache Log4j Vulnerability Workarounds
        Published Date:Dec 10, 2021
        Updated Date:Dec 10, 2021

          Workaround

          Logout4Shell
          Published Date:Dec 10, 2021
          Updated Date:Dec 10, 2021

            Version Update

            Apache Log4j 2 vulnerability
            Published Date:Dec 14, 2021
            Updated Date:Dec 14, 2021
            Source:Ubuntu21.04
            Affected Packages:

            liblog4j2-java-2.15.0

            Version Update

            Apache Log4j 2 vulnerability
            Published Date:Dec 14, 2021
            Updated Date:Dec 14, 2021
            Source:Ubuntu21.10
            Affected Packages:

            liblog4j2-java-2.15.0

            Version Update

            Apache Log4j 2 vulnerability
            Published Date:Dec 14, 2021
            Updated Date:Dec 14, 2021
            Source:Ubuntu18.04
            Affected Packages:

            liblog4j2-java-doc-2.10.0, liblog4j2-java-2.10.0

            Version Update

            Apache Log4j 2 vulnerability
            Published Date:Dec 14, 2021
            Updated Date:Dec 14, 2021
            Source:Ubuntu20.04
            Affected Packages:

            liblog4j2-java-2.15.0, liblog4j2-java-doc-2.15.0