netVigilance Vulnerability intelligence since 2004
CVE-2021-45046 · netVigilance record NV23-0055

Apache Log4j2 Deserialization of Untrusted Data

past due ransomware

What to do

Apply updates per vendor instructions.

CISA deadline 2023-05-22 · passed 3 years 3 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Who is affected

Apache Log4j2. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Weakness class: CWE-917.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 3 years 3 months ago

Sources