Executive brief
Apache Log4j2 contains an incomplete fix for CVE-2021-44228, allowing for deserialization of untrusted data. In certain non-default configurations, attackers can use JNDI Lookup patterns via Thread Context Map input to achieve remote code execution or information leaks.
Affected products
- Apache Log4j 2 2.0-beta9 to 2.15.0
Timeline
- 2021-12-14: disclosed: Initial public disclosure via mailing lists.
- 2023-05-01: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-12-16: patched: Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) released to fix the issue.
- 2023-05-01: exploited: Reported as exploited in the wild.