Skip to main content

Log4j2 vulnerabilities

2 published alerts for Apache Log4j2.

Actively exploited (KEV)Ransomware

CVE-2021-45046

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-45046). Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. CISA remediation due date: 2023-05-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-44228

Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-44228). Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. CISA remediation due date: 2021-12-24. If you need help checking exposure, call (864) 335-9223.