CRITICAL

CVE-2021-45046

Apache Log4j 2021-12-14 CVSS v3.1
CVSS
9
KEV

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Summary dbcve.org

CVE-2021-45046 is an incomplete fix for CVE-2021-44228 (Log4Shell) in Log4j 2.15.0. When using non-default Pattern Layout with Context Lookup ($${ctx:...}) or Thread Context Map patterns (%X, %mdc, %MDC), attackers controlling MDC input data can still inject malicious JNDI Lookup patterns to achieve information disclosure and remote/local code execution.

Mitigation

Upgrade to Log4j 2.16.0 (Java 8+) or 2.12.2 (Java 7), or manually remove message lookup pattern support and disable JNDI functionality by default.

Patch Commit

Weakness (CWE)

CWE-917

EPSS Score

99.98%
Probability of exploitation in next 30 days
100th percentile

References

http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List, Mitigation, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/12/15/3 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/12/18/1 Mailing List, Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ Mailing List, Release Notes https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ Mailing List, Release Notes https://logging.apache.org/log4j/2.x/security.html Mitigation, Release Notes, Vendor Advisory https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Third Party Advisory https://security.gentoo.org/glsa/202310-16 Third Party Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory https://www.cve.org/CVERecord?id=CVE-2021-44228 Not Applicable https://www.debian.org/security/2021/dsa-5022 Third Party Advisory https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory https://www.kb.cert.org/vuls/id/930724 Third Party Advisory, US Government Resource https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Third Party Advisory https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory https://www.oracle.com/security-alerts/cpujan2022.html Patch, Third Party Advisory https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE