CVE-2021-44228
Vulnerability Summary
Timeline
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVSS Metrics
- v3.1•CRITICAL•Score: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- v3.1•CRITICAL•Score: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H
- v2.0•HIGH•Score: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 100.00%• Percentile: 100%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
- CWE-502•Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
- CWE-917•Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
Affected Systems
- apache software foundation•apache log4j2
≥ 2.0-beta9, < log4j-core*
- apache•log4j
≥ 2.0.1, < 2.3.1 | ≥ 2.4.0, < 2.12.2 | ≥ 2.13.0, < 2.15.0 | 2.0 | 2.0:beta9 | 2.0:rc1 | 2.0:rc2
- apple•xcode
< 13.3
- bentley•synchro
≥ 6.1, < 6.2.4.2
- bentley•synchro_4d
< 6.4.3.2
- cisco•advanced_malware_protection_virtual_private_cloud_appliance
< 3.5.4
- cisco•automated_subsea_tuning
< 2.1.0 | 02.01.00
- cisco•broadworks
< 2021.11_1.162 | na
- cisco•business_process_automation
< 3.0.000.115 | ≥ 3.1.000.000, < 3.1.000.044 | ≥ 3.2.000.000, < 3.2.000.009
- cisco•cloud_connect
< 12.6\(1\)
- cisco•cloudcenter
< 4.10.0.16
- cisco•cloudcenter_cost_optimizer
< 5.5.2
- cisco•cloudcenter_suite
4.10.0.15 | 5.3.0 | 5.4.1 | 5.5.0 | 5.5.1
- cisco•cloudcenter_suite_admin
< 5.3.1
- cisco•cloudcenter_workload_manager
< 5.5.2
- cisco•common_services_platform_collector
< 2.9.1.3 | ≥ 2.10.0, < 2.10.0.1 | 002.009\(000.000\) | 002.009\(000.001\) | 002.009\(000.002\) | 002.009\(001.000\) | 002.009\(001.001\) | 002.009\(001.002\) | 002.010\(000.000\)
- cisco•connected_analytics_for_network_deployment
006.004.000.003 | 006.005.000. | 006.005.000.000 | 007.000.001 | 007.001.000 | 007.002.000 | 7.3 | 007.003.000 | 007.003.001.001 | 007.003.003 | 008.000.000 | 008.000.000.000.004
- cisco•connected_mobile_experiences
na
- cisco•contact_center_domain_manager
< 12.5\(1\)
- cisco•contact_center_management_portal
< 12.5\(1\)
- cisco•crosswork_data_gateway
< 2.0.2 | 3.0.0
- cisco•crosswork_network_automation
na | 2.0.0 | 3.0.0 | 4.1.0 | 4.1.1
- cisco•crosswork_network_controller
< 2.0.1 | 3.0.0
- cisco•crosswork_optimization_engine
< 2.0.1 | 3.0.0
- cisco•crosswork_platform_infrastructure
< 4.0.1 | 4.1.0
- cisco•crosswork_zero_touch_provisioning
< 2.0.1 | 3.0.0
- cisco•customer_experience_cloud_agent
< 1.12.1
- cisco•cx_cloud_agent
001.012
- cisco•cyber_vision
4.0.2
- cisco•cyber_vision_sensor_management_extension
< 4.0.3 | 4.0.2
- cisco•data_center_network_manager
< 11.3\(1\) | 11.3\(1\)
- cisco•dna_center
< 2.1.2.8 | ≥ 2.2.2.0, < 2.2.2.8 | ≥ 2.2.3.0, < 2.2.3.4 | 2.2.2.8
- cisco•dna_spaces
na
- cisco•dna_spaces_connector
na
- cisco•emergency_responder
< 11.5\(4\) | 11.5 | 11.5\(4.65000.14\) | 11.5\(4.66000.14\)
- cisco•enterprise_chat_and_email
< 12.0\(1\) | 12.0\(1\) | 12.5\(1\) | 12.6\(1\)
- cisco•evolved_programmable_network_manager
≤ 4.1.1 | 3.0 | 3.1 | 4.0 | 4.1 | 5.0 | 5.1
- cisco•finesse
< 12.6\(1\) | 12.6\(1\) | 12.5\(1\):su1 | 12.5\(1\):su2 | 12.6\(1\):es01 | 12.6\(1\):es02 | 12.6\(1\):es03
- cisco•firepower_threat_defense
6.2.3 | 6.3.0 | 6.4.0 | 6.5.0 | 6.6.0 | 6.7.0 | 7.0.0 | 7.1.0
- cisco•fog_director
na
- cisco•fxos
6.2.3 | 6.3.0 | 6.4.0 | 6.5.0 | 6.6.0 | 6.7.0 | 7.0.0 | 7.1.0
- cisco•identity_services_engine
< 2.4.0 | 2.4.0 | 002.004\(000.914\) | 002.006\(000.156\) | 002.007\(000.356\) | 003.000\(000.458\) | 003.001\(000.518\) | 003.002\(000.116\)
- cisco•integrated_management_controller_supervisor
< 2.3.2.1 | 002.003\(002.000\) | 2.3.2.0
- cisco•intersight_virtual_appliance
< 1.0.9-361 | 1.0.9-343
- cisco•iot_operations_dashboard
na
- cisco•mobility_services_engine
na
- cisco•network_assurance_engine
< 6.0.2 | 6.0\(2.1912\)
- cisco•network_dashboard_fabric_controller
11.0\(1\) | 11.1\(1\) | 11.2\(1\) | 11.3\(1\) | 11.4\(1\) | 11.5\(1\) | 11.5\(2\) | 11.5\(3\)
- cisco•network_insights_for_data_center
6.0\(2.1914\)
- cisco•network_services_orchestrator
< 5.3.5.1 | ≥ 5.4, < 5.4.5.2 | ≥ 5.5, < 5.5.4.1 | ≥ 5.6, < 5.6.3.1 | na
Showing first 50 affected entries in server-rendered view.
References (80)
- https://logging.apache.org/log4j/2.x/security.html
- http://www.openwall.com/lists/oss-security/2021/12/10/1
- http://www.openwall.com/lists/oss-security/2021/12/10/2
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
- http://www.openwall.com/lists/oss-security/2021/12/10/3
- https://security.netapp.com/advisory/ntap-20211210-0007/
- http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
- https://www.oracle.com/security-alerts/alert-cve-2021-44228.html
- https://www.debian.org/security/2021/dsa-5020
- https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/
- https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/
- http://www.openwall.com/lists/oss-security/2021/12/13/2
- http://www.openwall.com/lists/oss-security/2021/12/13/1
- http://www.openwall.com/lists/oss-security/2021/12/14/4
- https://www.kb.cert.org/vuls/id/930724
- https://twitter.com/kurtseifried/status/1469345530182455296
- https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf
- http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html
- http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html
- http://www.openwall.com/lists/oss-security/2021/12/15/3
- http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html
- http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html
- http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html
- http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html
- http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/
- http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
- https://www.oracle.com/security-alerts/cpujan2022.html
- http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html
- https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md
- http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2022/Mar/23
- https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001
- https://github.com/cisagov/log4j-affected-db
- https://support.apple.com/kb/HT213189
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228
- https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html
- http://seclists.org/fulldisclosure/2022/Jul/11
- http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html
- http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2022/Dec/2
- http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
- https://github.com/apache/logging-log4j2/pull/608
- https://github.com/github/advisory-database/pull/5501
- https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html
- https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html
- https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html
- https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
- https://seclists.org/fulldisclosure/2022/Dec/2
- https://seclists.org/fulldisclosure/2022/Jul/11
- https://seclists.org/fulldisclosure/2022/Mar/23
- https://security.netapp.com/advisory/ntap-20211210-0007
- https://github.com/advisories/GHSA-7rjr-3q55-vv33
- https://github.com/apache/logging-log4j2
- https://github.com/tangxiaofeng7/apache-log4j-poc
- https://issues.apache.org/jira/browse/LOG4J2-3198
- https://issues.apache.org/jira/browse/LOG4J2-3201
- https://issues.apache.org/jira/browse/LOG4J2-3214
- https://issues.apache.org/jira/browse/LOG4J2-3221
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM
- https://logging.apache.org/log4j/2.x/changes-report.html#a2.15.0
- https://logging.apache.org/log4j/2.x/manual/lookups.html#JndiLookup
- https://logging.apache.org/log4j/2.x/manual/migration.html
- https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2
- https://security-tracker.debian.org/tracker/CVE-2021-44228