Логотип exploitDog
bind:"BDU:2021-05969" OR bind:"CVE-2021-44228"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2021-05969" OR bind:"CVE-2021-44228"

Количество 15

Количество 15

fstec логотип

BDU:2021-05969

почти 4 года назад

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Критический
ubuntu логотип

CVE-2021-44228

почти 4 года назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический
redhat логотип

CVE-2021-44228

почти 4 года назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2021-44228

почти 4 года назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический
msrc логотип

CVE-2021-44228

почти 4 года назад

Apache Log4j Remote Code Execution Vulnerability

EPSS: Критический
debian логотип

CVE-2021-44228

почти 4 года назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2. ...

CVSS3: 10
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4109-1

почти 4 года назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:3999-1

почти 4 года назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1613-1

почти 4 года назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1586-1

почти 4 года назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1577-1

почти 4 года назад

Security update for log4j

EPSS: Критический
github логотип

GHSA-jfh8-c2jp-5v3q

почти 4 года назад

Remote code injection in Log4j

CVSS3: 10
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4107-1

почти 4 года назад

Security update for log4j

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:4094-1

почти 4 года назад

Security update for log4j

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1601-1

почти 4 года назад

Security update for log4j

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-05969

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
94%
Критический
почти 4 года назад
ubuntu логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
94%
Критический
почти 4 года назад
redhat логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
94%
Критический
почти 4 года назад
nvd логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
94%
Критический
почти 4 года назад
msrc логотип
CVE-2021-44228

Apache Log4j Remote Code Execution Vulnerability

94%
Критический
почти 4 года назад
debian логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2. ...

CVSS3: 10
94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:4109-1

Security update for logback

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:3999-1

Security update for log4j

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1586-1

Security update for log4j

94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1577-1

Security update for log4j

94%
Критический
почти 4 года назад
github логотип
GHSA-jfh8-c2jp-5v3q

Remote code injection in Log4j

CVSS3: 10
94%
Критический
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:4107-1

Security update for log4j

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:4094-1

Security update for log4j

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1601-1

Security update for log4j

почти 4 года назад

Уязвимостей на страницу