CVE-2021-45046

Description from NVD

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Information Acquisition Date:2022-08-24T18:48Z
CVSS 2.0: 5.1 MEDIUM CVSS 3.x: 9.0 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

▼ CVSS2 Vec AV:N/AC:H/Au:N/C:P/I:P/A:P

NVD References

 [oss-security] 20211214 CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
     source:MLIST
     tags:Mailing List    Mitigation    Third Party Advisory    
 https://logging.apache.org/log4j/2.x/security.html
     source:MISC
     tags:Mitigation    Release Notes    Vendor Advisory    
 https://www.cve.org/CVERecord?id=CVE-2021-44228
     source:MISC
     tags:Not Applicable    
 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html
     source:CONFIRM
     tags:Third Party Advisory    
 20211210 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
     source:CISCO
     tags:Third Party Advisory    
 [oss-security] 20211215 Re: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
     source:MLIST
     tags:Mailing List    Third Party Advisory    
 https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf
     source:CONFIRM
     tags:Third Party Advisory    
 VU#930724
     source:CERT-VN
     tags:Third Party Advisory    US Government Resource    
 https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf
     source:CONFIRM
     tags:Third Party Advisory    
 DSA-5022
     source:DEBIAN
     tags:Third Party Advisory    
 https://www.oracle.com/security-alerts/alert-cve-2021-44228.html
     source:CONFIRM
     tags:Third Party Advisory    
 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
     source:CONFIRM
     tags:Third Party Advisory    
 [oss-security] 20211218 Re: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
     source:MLIST
     tags:Mailing List    Third Party Advisory    
 https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf
     source:CONFIRM
     tags:Third Party Advisory    
 https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
     source:CONFIRM
     tags:Third Party Advisory    
 FEDORA-2021-5c9d12a93e
     source:FEDORA
     tags:Mailing List    Third Party Advisory    
 FEDORA-2021-abbe24e41c
     source:FEDORA
     tags:Mailing List    Third Party Advisory    
 https://www.oracle.com/security-alerts/cpujan2022.html
     source:MISC
     tags:Patch    Third Party Advisory    
 https://www.oracle.com/security-alerts/cpuapr2022.html
     source:MISC
     tags:
 N/A
     source:N/A
     tags:

This vulnerability may involve a PoC.

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
http://vulmon.com/vulnerabilitydetails?qid=CVE1983
https://alerts.vulmon.com/?utm_source=twitter&utm_medium=so...251
https://www.oracle.com/security-alerts/cpujan2022.html54
https://cvetrends.com48
https://www.reddit.com/r/blueteamsec/comments/rd38z9/log4j_...38
http://twinybots.ch23
http://cyberiqs.com/latestnews19
https://www.jpcert.or.jp/at/2021/at210050.html16
https://lists.astaro.com/ASGV9-IPS-rules.html#013
https://ift.tt/3pW2kds10
https://www.truesec.com/hub/blog/apache-log4j-injection-vul...10
https://www.techsolvency.com/story-so-far/cve-2021-44228-lo...9
https://lists.apache.org/thread/83y7dx5xvn3h5290q1twn16tlto...8
https://aws.amazon.com/jp/security/security-bulletins/AWS-2...7
https://www.cybereason.com/blog/cybereason-releases-vaccine...7
https://gigazine.net/news/20211216-log4j-log4shell-cve-2021...6
https://logging.apache.org/log4j/2.x/security.html6
http://earmas.ga5
https://opsmtrs.com/3xP0zlo5
https://www.intel.com/content/www/us/en/security-center/adv...5
https://www.zdnet.com/article/second-log4j-vulnerability-fo...5
http://www.kitploit.com/2021/12/log4j-detector-detects-log4...5
https://github.com/NCSC-NL/log4shell/tree/main/software4
https://sysdig.com/blog/exploit-detect-mitigate-log4j-cve4
https://github.blog/2021-12-13-githubs-response-to-log4j-vu...4
https://www.snort.org/downloads4
https://tools.cisco.com/security/center/content/CiscoSecuri...4
https://about.gitlab.com/blog/2021/12/15/updates-and-action...4
https://tweetedtimes.com/v/21183?s=tnp4
https://security.sios.com/vulnerability/misc-security-vulne...4
https://news.ycombinator.com/item?id=295615324
https://blog.segu-info.com.ar/2021/12/resumen-de-todos-los-...4
https://www.hackingarticles.in/a-detailed-guide-on-log4j-pe...4
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf4
https://cloudsecurityalliance.org/articles/log4j-the-evolut...4
https://bit.ly/3q0PPgA3
https://buff.ly/3oTpaDe3
https://cybr.ly/31F2cXL3
https://hclsw.co/hoge7x3
https://youtu.be/_sC7ntv0PUY3
http://apache.org3
http://codezine.jp/article/detail/153463
https://twitter.com/likethecoins/status/14708287947558297653
https://www.cve.org/CVERecord?id=CVE-2021-450463
http://mi6rogue.com/blog3
https://www.cisa.gov/uscert/apache-log4j-vulnerability-guid...3
https://docs.jamf.com/technical-articles/Mitigating_the_Apa...3
https://guardedbox.es3
https://kb.tableau.com/articles/issue/Apache-Log4j2-vulnera...3
https://opensearch.org/blog/releases/2021/12/update-to-1-2-1/3
https://www.govcert.ch/blog/zero-day-exploit-targeting-popu...3
https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-...3
https://www.splunk.com/en_us/blog/bulletins/splunk-security...3
https://www.vmware.com/security/advisories/VMSA-2021-0028.html3
https://core.vmware.com/vmsa-2021-0028-questions-answers-faq3
https://support.sap.com/content/dam/support/en_us/library/s...3
https://www.access42.nl/nieuws/cve-2021-44228-proof-of-conc...3
https://www.tableau.com/about/blog/2021/12/update-apache-lo...3
https://www.tenable.com/blog/cve-2021-44228-cve-2021-45046-...3
https://blog.aquasec.com/second-log4j-security-vulnerability3
https://community.ui.com/releases/UniFi-Network-Application...3
https://www.openwall.com/lists/oss-security/2021/12/14/43
https://access.redhat.com/security/cve/cve-2021-450463
https://thehackernews.com/2021/12/second-log4j-vulnerabilit...3
https://support.citrix.com/article/CTX3357053
https://www.praetorian.com/blog/log4j-2-15-0-stills-allows-...3
https://www.solarwinds.com/trust-center/security-advisories...3
https://blog.cloudflare.com/protection-against-cve-2021-450...3
https://securityonline.info/log4j-detector-detects-vulnerab...3
https://blogs.networld.co.jp/entry/2021/12/12/2105293
https://www.cert.ssi.gouv.fr/alerte/CERTFR-2021-ALE-022/3
https://noticiasseguridad.com/vulnerabilidades/detalles-de-...3
https://www.alexvanwolferen.nl/sitecore-solr-fix-log4j-cve-...3
https://anchisesbr.blogspot.com/2021/12/seguranca-o-caos-do...3
https://www.bleepingcomputer.com/news/security/cisa-release...3
https://ipssignatures.appspot.com/?cve=CVE-2021-450463
https://blog.talosintelligence.com/2021/12/apache-log4j-rce...3
https://log4j-tester.trendmicro.com/3
https://security.paloaltonetworks.com/CVE-2021-442283

Information from Twitter

User URL Info Source Date
fletch_ai https://bit.ly/3ZSDADv Source fletch_ai        1636584407820632064 2023/03/17

List of frequently cited URLs

URLNum of Times Referred to
vulmon.com1983
alerts.vulmon.com251
www.oracle.com54
cvetrends.com48
www.reddit.com38
twinybots.ch23
cyberiqs.com19
www.jpcert.or.jp16
lists.astaro.com13
ift.tt10
www.truesec.com10
www.techsolvency.com9
lists.apache.org8
aws.amazon.com7
www.cybereason.com7
gigazine.net6
logging.apache.org6
earmas.ga5
opsmtrs.com5
www.intel.com5
www.zdnet.com5
www.kitploit.com5
github.com4
sysdig.com4
github.blog4
www.snort.org4
tools.cisco.com4
about.gitlab.com4
tweetedtimes.com4
security.sios.com4
news.ycombinator.com4
blog.segu-info.com.ar4
www.hackingarticles.in4
cert-portal.siemens.com4
cloudsecurityalliance.org4
bit.ly3
buff.ly3
cybr.ly3
hclsw.co3
youtu.be3
apache.org3
codezine.jp3
twitter.com3
www.cve.org3
mi6rogue.com3
www.cisa.gov3
docs.jamf.com3
guardedbox.es3
kb.tableau.com3
opensearch.org3
www.govcert.ch3
www.lunasec.io3
www.splunk.com3
www.vmware.com3
core.vmware.com3
support.sap.com3
www.access42.nl3
www.tableau.com3
www.tenable.com3
blog.aquasec.com3
community.ui.com3
www.openwall.com3
access.redhat.com3
thehackernews.com3
support.citrix.com3
www.praetorian.com3
www.solarwinds.com3
blog.cloudflare.com3
securityonline.info3
blogs.networld.co.jp3
www.cert.ssi.gouv.fr3
noticiasseguridad.com3
www.alexvanwolferen.nl3
anchisesbr.blogspot.com3
www.bleepingcomputer.com3
ipssignatures.appspot.com3
blog.talosintelligence.com3
log4j-tester.trendmicro.com3
security.paloaltonetworks.com3

Information from Twitter

User URL Info Source
fletch_ai bit.ly Show Tweet

GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2023/03/17 Score : 1
Added Har-sia Database : 2021/12/15
Last Modified : 2023/03/17
Highest Scored Date : 2021/12/15
Highest Score : 568