Junglewise Threat Intelligence

CVE-2021-45046: Incomplete fix for Apache Log4j vulnerability

CVE-2021-45046 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-12-14

Technologies: Apache Log4j2. Vendors: Apache.

Executive brief

Apache Log4j2 contains an incomplete fix for CVE-2021-44228, allowing for deserialization of untrusted data. In certain non-default configurations, attackers can use JNDI Lookup patterns via Thread Context Map input to achieve remote code execution or information leaks.

Affected products

  • Apache Log4j 2 2.0-beta9 to 2.15.0

Timeline

  • 2021-12-14: disclosed: Initial public disclosure via mailing lists.
  • 2023-05-01: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-12-16: patched: Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) released to fix the issue.
  • 2023-05-01: exploited: Reported as exploited in the wild.

Related threats