Логотип exploitDog
bind:"CVE-2021-44228"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-44228"

Количество 15

Количество 15

ubuntu логотип

CVE-2021-44228

больше 3 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический
redhat логотип

CVE-2021-44228

больше 3 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2021-44228

больше 3 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический
msrc логотип

CVE-2021-44228

больше 3 лет назад

Apache Log4j Remote Code Execution Vulnerability

EPSS: Критический
debian логотип

CVE-2021-44228

больше 3 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2. ...

CVSS3: 10
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4109-1

больше 3 лет назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:3999-1

больше 3 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1613-1

больше 3 лет назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1586-1

больше 3 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1577-1

больше 3 лет назад

Security update for log4j

EPSS: Критический
github логотип

GHSA-jfh8-c2jp-5v3q

больше 3 лет назад

Remote code injection in Log4j

CVSS3: 10
EPSS: Критический
fstec логотип

BDU:2021-05969

больше 3 лет назад

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4107-1

больше 3 лет назад

Security update for log4j

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:4094-1

больше 3 лет назад

Security update for log4j

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1601-1

больше 3 лет назад

Security update for log4j

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
94%
Критический
больше 3 лет назад
redhat логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
94%
Критический
больше 3 лет назад
nvd логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
94%
Критический
больше 3 лет назад
msrc логотип
CVE-2021-44228

Apache Log4j Remote Code Execution Vulnerability

94%
Критический
больше 3 лет назад
debian логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2. ...

CVSS3: 10
94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4109-1

Security update for logback

94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3999-1

Security update for log4j

94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1586-1

Security update for log4j

94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1577-1

Security update for log4j

94%
Критический
больше 3 лет назад
github логотип
GHSA-jfh8-c2jp-5v3q

Remote code injection in Log4j

CVSS3: 10
94%
Критический
больше 3 лет назад
fstec логотип
BDU:2021-05969

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
94%
Критический
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4107-1

Security update for log4j

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4094-1

Security update for log4j

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1601-1

Security update for log4j

больше 3 лет назад

Уязвимостей на страницу