Junglewise Threat Intelligence

CVE-2021-44228: Remote code injection in Log4j

CVE-2021-44228 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-12-10

Technologies: Apache Log4j2. Vendors: Apache.

Executive brief

Apache Log4j2 JNDI features do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.

Affected products

  • Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1)

Timeline

  • 2021-12-10: disclosed
  • 2021-12-10: advisory

Related threats