CVE-2021-44832
MEDIUMRansomware
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
Record summary
CVE-2021-44832 has a selected CVSS score of 6.6 (medium); EIP currently links 4 repository PoCs. VulnCheck reports CVE-2021-44832 use in known ransomware campaigns.
Description
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 14, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Available material
- Repository PoCs
- 4
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 29, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Apache Log4j2Browse Apache Software Foundation / Apache Log4j2 | CVE List | log4j-core to < 2.17.1 | affected |
org.apache.logging.log4j:log4j-coreBrowse Maven / org.apache.logging.log4j:log4j-core | GitHub Advisory | 2.0-beta7 to < 2.3.2 · Fixed in 2.3.2 | affected |
| 2.4 to < 2.12.4 · Fixed in 2.12.4 | affected | ||
| 2.13.0 to < 2.17.1 · Fixed in 2.17.1 | affected | ||
org.ops4j.pax.logging:pax-logging-log4j2Browse Maven / org.ops4j.pax.logging:pax-logging-log4j2 | GitHub Advisory | 1.8.0 to < 1.9.2 · Fixed in 1.9.2 | affected |
| 1.10.0 to < 1.10.9 · Fixed in 1.10.9 | affected | ||
| 1.11.0 to < 1.11.13 · Fixed in 1.11.13 | affected | ||
| 2.0.0 to < 2.0.14 · Fixed in 2.0.14 | affected | ||
Proofs of concept
4Repository PoCs
GitHubthedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832Repository PoCby thedevappsecguyStars: 2Not analyzed1 file
GitHubandalik/log4j-filescanRepository PoCby andalikStars: 1Not analyzed4 files
GitHubcckuailong/log4j_RCE_CVE-2021-44832Repository PoCby cckuailongStars: 4Not analyzed14 files
GitHubname/log4j-scannerRepository PoCby nameStars: 1Not analyzed6 files
References
Showing 12 of 17[oss-security] 20211228 CVE-2021-44832: Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configurationmailing list
http://www.openwall.com/lists/oss-security/2021/12/28/1 cert-portal.siemens.comConfirmation
https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf github.com
https://github.com/apache/logging-log4j2 issues.apache.org
https://issues.apache.org/jira/browse/LOG4J2-3293 lists.apache.org
https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143 [debian-lts-announce] 20211229 [SECURITY] [DLA 2870-1] apache-log4j2 security updatemailing list
https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html FEDORA-2021-c6f471ce0fVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA FEDORA-2021-1bd9151babVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRA lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFC nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-44832 sec.cloudapps.cisco.com
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd