SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-45105

This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted.

MEDIUM 5.9EPSS 100.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-674
Affected
apache/log4j · netapp/cloud manager · debian/debian linux · sonicwall/email security · sonicwall/network security manager · sonicwall/web application firewall · sonicwall/6bk1602-0aa12-0tp0 firmware · sonicwall/6bk1602-0aa22-0tp0 firmware · sonicwall/6bk1602-0aa32-0tp0 firmware · sonicwall/6bk1602-0aa42-0tp0 firmware · sonicwall/6bk1602-0aa52-0tp0 firmware · oracle/agile engineering data management · oracle/agile plm mcad connector · oracle/agile product lifecycle management · oracle/autovue for agile product lifecycle management · oracle/banking deposits and lines of credit servicing · oracle/banking enterprise default management · oracle/banking loans servicing · oracle/banking party management · oracle/banking payments · +40 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.