Логотип exploitDog
product: "log4j"
Консоль
Логотип exploitDog

exploitDog

product: "log4j"
Apache Log4j

Apache Log4jбиблиотека журналирования (логирования) Java-программ

Релизный цикл, информация об уязвимостях

Продукт: Apache Log4j
Вендор: apache

График релизов

122.32.1220012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026

Недавние уязвимости Apache Log4j

Количество 106

debian логотип

CVE-2021-44832

больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
EPSS: Средний
ubuntu логотип

CVE-2021-44832

больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1631-1

больше 3 лет назад

Security update for kafka

EPSS: Высокий
redhat логотип

CVE-2021-44832

больше 3 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1613-1

больше 3 лет назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1612-1

больше 3 лет назад

Security update for log4j12

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:1605-1

больше 3 лет назад

Security update for log4j

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:4118-1

больше 3 лет назад

Security update for log4j

EPSS: Средний
github логотип

GHSA-p6xc-xr62-6r2g

больше 3 лет назад

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
EPSS: Средний
nvd логотип

CVE-2021-45105

больше 3 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
47%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
47%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1631-1

Security update for kafka

73%
Высокий
больше 3 лет назад
redhat логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
47%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1612-1

Security update for log4j12

73%
Высокий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1605-1

Security update for log4j

65%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4118-1

Security update for log4j

65%
Средний
больше 3 лет назад
github логотип
GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
65%
Средний
больше 3 лет назад
nvd логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
65%
Средний
больше 3 лет назад

Уязвимостей на страницу


Поделиться