Record summary

CVE-2021-44832 has a selected CVSS score of 6.6 (medium); EIP currently links 4 repository PoCs. VulnCheck reports CVE-2021-44832 use in known ransomware campaigns.

Description

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Repository PoCs
4

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 29, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE Listlog4j-core to < 2.17.1affected

org.apache.logging.log4j:log4j-core

Browse Maven / org.apache.logging.log4j:log4j-core
GitHub Advisory2.0-beta7 to < 2.3.2 · Fixed in 2.3.2affected
2.4 to < 2.12.4 · Fixed in 2.12.4affected
2.13.0 to < 2.17.1 · Fixed in 2.17.1affected

org.ops4j.pax.logging:pax-logging-log4j2

Browse Maven / org.ops4j.pax.logging:pax-logging-log4j2
GitHub Advisory1.8.0 to < 1.9.2 · Fixed in 1.9.2affected
1.10.0 to < 1.10.9 · Fixed in 1.10.9affected
1.11.0 to < 1.11.13 · Fixed in 1.11.13affected
2.0.0 to < 2.0.14 · Fixed in 2.0.14affected

Proofs of concept

4

Repository PoCs

GitHubthedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832Repository PoCby thedevappsecguyStars: 2Not analyzed1 file

15.9 KiB · linked to 4 vulnerabilities

GitHub

PoC details
GitHubandalik/log4j-filescanRepository PoCby andalikStars: 1Not analyzed4 files

200.9 KiB · linked to 4 vulnerabilities

GitHub

PoC details
GitHubcckuailong/log4j_RCE_CVE-2021-44832Repository PoCby cckuailongStars: 4Not analyzed14 files

1.0 MiB

GitHub

PoC details
GitHubname/log4j-scannerRepository PoCby nameStars: 1Not analyzed6 files

39.2 KiB

GitHub

PoC details

References

Showing 12 of 17