CVE-2021-45105
This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-674
- Affected
- apache/log4j · netapp/cloud manager · debian/debian linux · sonicwall/email security · sonicwall/network security manager · sonicwall/web application firewall · sonicwall/6bk1602-0aa12-0tp0 firmware · sonicwall/6bk1602-0aa22-0tp0 firmware · sonicwall/6bk1602-0aa32-0tp0 firmware · sonicwall/6bk1602-0aa42-0tp0 firmware · sonicwall/6bk1602-0aa52-0tp0 firmware · oracle/agile engineering data management · oracle/agile plm mcad connector · oracle/agile product lifecycle management · oracle/autovue for agile product lifecycle management · oracle/banking deposits and lines of credit servicing · oracle/banking enterprise default management · oracle/banking loans servicing · oracle/banking party management · oracle/banking payments · +40 more
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2021/12/19/1Mailing List, Mitigation, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdfThird Party Advisory
- https://logging.apache.org/log4j/2.x/security.htmlRelease Notes, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211218-0001/Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdThird Party Advisory
- https://www.debian.org/security/2021/dsa-5024Third Party Advisory
- https://www.kb.cert.org/vuls/id/930724Third Party Advisory, US Government Resource
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1541/Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2021/12/19/1Mailing List, Mitigation, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdfThird Party Advisory
- https://logging.apache.org/log4j/2.x/security.htmlRelease Notes, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211218-0001/Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdThird Party Advisory
- https://www.debian.org/security/2021/dsa-5024Third Party Advisory
- https://www.kb.cert.org/vuls/id/930724Third Party Advisory, US Government Resource
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1541/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.