Логотип exploitDog
product: "log4j"
Консоль
Логотип exploitDog

exploitDog

product: "log4j"
Apache Log4j

Apache Log4jбиблиотека журналирования (логирования) Java-программ

Релизный цикл, информация об уязвимостях

Продукт: Apache Log4j
Вендор: apache

График релизов

122.32.12200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027

Недавние уязвимости Apache Log4j

Количество 106

debian логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
EPSS: Средний
ubuntu логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1631-1

почти 4 года назад

Security update for kafka

EPSS: Высокий
redhat логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1613-1

почти 4 года назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1612-1

почти 4 года назад

Security update for log4j12

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:1605-1

почти 4 года назад

Security update for log4j

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:4118-1

почти 4 года назад

Security update for log4j

EPSS: Высокий
github логотип

GHSA-p6xc-xr62-6r2g

около 4 лет назад

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
EPSS: Высокий
nvd логотип

CVE-2021-45105

около 4 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
50%
Средний
почти 4 года назад
ubuntu логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
50%
Средний
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1631-1

Security update for kafka

72%
Высокий
почти 4 года назад
redhat логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
50%
Средний
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1612-1

Security update for log4j12

72%
Высокий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1605-1

Security update for log4j

72%
Высокий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:4118-1

Security update for log4j

72%
Высокий
почти 4 года назад
github логотип
GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
72%
Высокий
около 4 лет назад
nvd логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
72%
Высокий
около 4 лет назад

Уязвимостей на страницу


Поделиться