CVE-2021-44228
Apache Log4j2 Remote Code Execution Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Log4j2, fix it now.
CISA required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
US federal civilian agencies must remediate by Dec 24, 2021.
Patch status
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Affected versions | Fixed in | Source |
|---|---|---|---|---|
| Identity Services Engine | Cisco | < 2.4.0; 2.4.0; 002.004\(000.914\); 002.006\(000.156\); 002.007\(000.356\); 003.000\(000.458\) | 2.4.0 | NVD |
| Log4j2 | Apache Software Foundation | — | — | KEV |
| SonicWall Email Security | SonicWall | < 10.0.13 | 10.0.13 | NVD |
| Unified Communications Manager | Cisco | < 11.5\(1\); 11.5\(1\); 11.5\(1\)su3; 11.5\(1.17900.52\); 11.5\(1.18119.2\); 11.5\(1.18900.97\) | 11.5\(1\) | NVD |
Sources: NVD = NIST National Vulnerability Database; KEV = CISA Known Exploited Vulnerabilities catalog.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdateKEV
CVE-2021-44228 scored CVSS 10.0: Apache Log4j2, Apache Log4j2 Remote Code Execution Vulnerability
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Log4j2 systems are exposed to active attacks now.
Basis: NIST National Vulnerability Database
- Patch releasedUpdateKEV
Patch released for CVE-2021-44228: Apache Log4j2, Apache Log4j2 Remote Code Execution Vulnerability
An official fix is now available for Apache Log4j2. This vulnerability is being exploited, so apply it promptly.
Basis: NVD patch reference
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
References
- nvd.nist.gov
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- seclists.org
- seclists.org
- seclists.org
- openwall.com
- openwall.com
- openwall.com
- openwall.com
- openwall.com
- openwall.com
- openwall.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- cert-portal.siemens.com
