PT-2021-5610 · Apache+6 · Apache Log4J2+6

Published

2021-12-18

·

Updated

2026-05-29

·

CVE-2021-44832

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4)
Description The issue is related to the absence of additional access control elements for JNDI in the Apache Log4j2 library. This can allow a remote attacker to execute arbitrary code using a JDBC Appender with a JNDI LDAP data source URI when the attacker has control of the target LDAP server. The problem requires specific conditions for exploitation, including the ability to modify the Log4j configuration file. There have been real-world incidents where this issue was exploited, with breaches reported at Sisense and Snowflake, posing a severe threat to global finance.
Recommendations For Apache Log4j2 versions 2.0-beta7 through 2.17.0, update to version 2.17.1, 2.12.4, or 2.3.2 to fix the issue by limiting JNDI data source names to the java protocol. As a temporary workaround, consider restricting access to the JDBC Appender with a JNDI LDAP data source URI to minimize the risk of exploitation. Avoid using the log4j2.configurationFile parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2022-7659
BDU:2022-00044
CVE-2021-44832
DLA-2870-1
GHSA-8489-44MV-GGJ8
MGASA-2022-0002
OESA-2021-1481
OESA-2022-1956
OESA-2022-1957
OPENSUSE-SU-2021:4208-1
OPENSUSE-SU-2021_4208-1
OPENSUSE-SU-2022:0002-1
OPENSUSE-SU-2022_0002-1
OPENSUSE-SU-2024:11702-1
RHSA-2022:1296
RHSA-2022:1297
USN-5222-1

Affected Products

Alt Linux
Apache Log4J2
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu