PT-2021-5597 · Apache+9 · Log4J+9
Published
2021-12-10
·
Updated
2026-05-22
·
CVE-2021-4104
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Log4j version 1.2
Description
The issue is related to the JMSAppender in Log4j 1.2, which is vulnerable to deserialization of untrusted data. An attacker with write access to the Log4j configuration can provide
TopicBindingName and TopicConnectionFactoryBindingName configurations, causing JMSAppender to perform JNDI requests that result in remote code execution. This issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015.Recommendations
For Log4j version 1.2, upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. As a temporary workaround, consider disabling the JMSAppender until a patch is available. Restrict access to the JMSAppender configuration to minimize the risk of exploitation. Avoid using the
TopicBindingName and TopicConnectionFactoryBindingName configurations in the affected Log4j configuration until the issue is resolved.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Jira
Linuxmint
Log4J
Red Hat
Rocky Linux
Suse
Ubuntu