Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2021-44832

больше 4 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Критический
redhat логотип

CVE-2021-44832

больше 4 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Критический
nvd логотип

CVE-2021-44832

больше 4 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
EPSS: Критический
debian логотип

CVE-2021-44832

больше 4 лет назад

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2022:0002-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4208-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
github логотип

GHSA-8489-44mv-ggj8

больше 4 лет назад

Improper Input Validation and Injection in Apache Log4j2

CVSS3: 6.6
EPSS: Критический
fstec логотип

BDU:2022-00044

больше 4 лет назад

Уязвимость библиотеки журналирования Java-программ Apache Log4j2, связанная с отсутствием дополнительных элементов управления доступом JNDI, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.6
EPSS: Критический
redos логотип

ROS-20220125-04

больше 4 лет назад

Уязвимость библиотеки журналирования Java-программ Apache Log4j2

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
98%
Критический
больше 4 лет назад
redhat логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
98%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS3: 6.6
98%
Критический
больше 4 лет назад
debian логотип
CVE-2021-44832

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fi ...

CVSS3: 6.6
98%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0002-1

Security update for log4j

98%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4208-1

Security update for log4j

98%
Критический
больше 4 лет назад
github логотип
GHSA-8489-44mv-ggj8

Improper Input Validation and Injection in Apache Log4j2

CVSS3: 6.6
98%
Критический
больше 4 лет назад
fstec логотип
BDU:2022-00044

Уязвимость библиотеки журналирования Java-программ Apache Log4j2, связанная с отсутствием дополнительных элементов управления доступом JNDI, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.6
98%
Критический
больше 4 лет назад
redos логотип
ROS-20220125-04

Уязвимость библиотеки журналирования Java-программ Apache Log4j2

98%
Критический
больше 4 лет назад

Уязвимостей на страницу