Логотип exploitDog
product: "log4j"
Консоль
Логотип exploitDog

exploitDog

product: "log4j"
Apache Log4j

Apache Log4jбиблиотека журналирования (логирования) Java-программ

Релизный цикл, информация об уязвимостях

Продукт: Apache Log4j
Вендор: apache

График релизов

122.32.1220012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026

Недавние уязвимости Apache Log4j

Количество 106

debian логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
EPSS: Средний
ubuntu логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1631-1

почти 4 года назад

Security update for kafka

EPSS: Высокий
redhat логотип

CVE-2021-44832

почти 4 года назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:1613-1

почти 4 года назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1612-1

почти 4 года назад

Security update for log4j12

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:1605-1

почти 4 года назад

Security update for log4j

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:4118-1

почти 4 года назад

Security update for log4j

EPSS: Средний
github логотип

GHSA-p6xc-xr62-6r2g

почти 4 года назад

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
EPSS: Средний
nvd логотип

CVE-2021-45105

почти 4 года назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
35%
Средний
почти 4 года назад
ubuntu логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
35%
Средний
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1631-1

Security update for kafka

74%
Высокий
почти 4 года назад
redhat логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
35%
Средний
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1612-1

Security update for log4j12

74%
Высокий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1605-1

Security update for log4j

66%
Средний
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:4118-1

Security update for log4j

66%
Средний
почти 4 года назад
github логотип
GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
66%
Средний
почти 4 года назад
nvd логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
66%
Средний
почти 4 года назад

Уязвимостей на страницу


Поделиться