Vulnerability record

CVE-2021-44228

Apache Log4j2 Remote Code Execution Vulnerability

Severity: CriticalExploitation: Exploitation confirmedCISA KEV Used by ransomware
What should I do?

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Log4j2, fix it now.

CISA required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

US federal civilian agencies must remediate by Dec 24, 2021.

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: NVD patch reference

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorAffected versionsFixed inSource
Identity Services EngineCisco< 2.4.0; 2.4.0; 002.004\(000.914\); 002.006\(000.156\); 002.007\(000.356\); 003.000\(000.458\)2.4.0NVD
Log4j2Apache Software Foundation——KEV
SonicWall Email SecuritySonicWall< 10.0.1310.0.13NVD
Unified Communications ManagerCisco< 11.5\(1\); 11.5\(1\); 11.5\(1\)su3; 11.5\(1.17900.52\); 11.5\(1.18119.2\); 11.5\(1.18900.97\)11.5\(1\)NVD

Sources: NVD = NIST National Vulnerability Database; KEV = CISA Known Exploited Vulnerabilities catalog.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdateKEV

    CVE-2021-44228 scored CVSS 10.0: Apache Log4j2, Apache Log4j2 Remote Code Execution Vulnerability

    CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Log4j2 systems are exposed to active attacks now.

    Basis: NIST National Vulnerability Database

  2. Patch releasedUpdateKEV

    Patch released for CVE-2021-44228: Apache Log4j2, Apache Log4j2 Remote Code Execution Vulnerability

    An official fix is now available for Apache Log4j2. This vulnerability is being exploited, so apply it promptly.

    Basis: NVD patch reference

1 earlier event is available with a subscription. See plans.

Coverage

We have not published a story about this vulnerability yet.

References