Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-44832

Опубликовано: 28 дек. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 8.5
CVSS3: 6.6

Описание

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

РелизСтатусПримечание
bionic

released

2.12.4-0ubuntu0.1
devel

needs-triage

esm-apps/bionic

released

2.12.4-0ubuntu0.1
esm-apps/focal

released

2.17.1-0.20.04.1
esm-apps/jammy

not-affected

2.17.1-1
esm-apps/noble

needs-triage

esm-infra-legacy/trusty

DNE

esm-infra/xenial

needed

focal

released

2.17.1-0.20.04.1
hirsute

released

2.17.1-0.21.04.1

Показывать по

8.5 High

CVSS2

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
redhat
больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
nvd
больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
debian
больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

suse-cvrf
больше 3 лет назад

Security update for log4j

suse-cvrf
больше 3 лет назад

Security update for log4j

8.5 High

CVSS2

6.6 Medium

CVSS3