CVE-2021-45046

CRITICAL KEV RANSOMWARE NUCLEI

Apache Log4j < 2.12.2 - Remote Code Execution

Title source: rule

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Exploits (14)

nomisec SCANNER 84 stars
by lijiejie · poc
https://github.com/lijiejie/log4j2_vul_local_scanner
nomisec WORKING POC 21 stars
by cckuailong · remote
https://github.com/cckuailong/Log4j_CVE-2021-45046
nomisec SCANNER 14 stars
by mergebase · poc
https://github.com/mergebase/log4j-samples
nomisec WORKING POC 6 stars
by ifconfig-me · remote
https://github.com/ifconfig-me/Log4Shell-Payloads
nomisec WRITEUP 4 stars
by BobTheShoplifter · poc
https://github.com/BobTheShoplifter/CVE-2021-45046-Info
nomisec WRITEUP 1 stars
by ludy-dev · infoleak
https://github.com/ludy-dev/cve-2021-45046
gitlab WORKING POC
by xantho09-cs5439 · poc
https://gitlab.com/xantho09-cs5439/second-log4j
nomisec STUB
by shaily29-eng · poc
https://github.com/shaily29-eng/CyberSecurity_CVE-2021-45046
nomisec SCANNER
by lukepasek · poc
https://github.com/lukepasek/log4jjndilookupremove
nomisec SCANNER
by CaptanMoss · poc
https://github.com/CaptanMoss/Log4Shell-Sandbox-Signature
nomisec WORKING POC
by tejas-nagchandi · poc
https://github.com/tejas-nagchandi/CVE-2021-45046
nomisec WORKING POC
by pravin-pp · poc
https://github.com/pravin-pp/log4j2-CVE-2021-45046
metasploit SCANNER
by Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/log4shell_scanner.rb

Nuclei Templates (2)

Apache Log4j2 - Remote Code Injection
CRITICALby princechaddha
Apache Log4j2 - Remote Code Injection
CRITICALby ImNightmaree

References (22)

... and 2 more

Scores

CVSS v3 9.0
EPSS 0.9434
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2023-05-01
VulnCheck KEV 2021-12-06
InTheWild.io 2022-05-30
ENISA EUVD EUVD-2021-34769
Ransomware Use Confirmed
CWE
CWE-917
Status published
Products (46)
apache/log4j 2.0 (4 CPE variants)
apache/log4j 2.0.1 - 2.12.2
cvat/computer_vision_annotation_tool
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
intel/audio_development_kit
intel/datacenter_manager
intel/genomics_kernel_library
... and 36 more
Published Dec 14, 2021
KEV Added May 01, 2023
Tracked Since Feb 18, 2026