CVE-2021-45105
MEDIUM EXPLOITED RANSOMWAREApache Log4j < 2.3.1 - Improper Input Validation
Title source: ruleDescription
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Exploits (11)
nomisec
WORKING POC
13 stars
by cckuailong · poc
https://github.com/cckuailong/Log4j_dos_CVE-2021-45105
nomisec
WORKING POC
by dileepdkumar · poc
https://github.com/dileepdkumar/https-github.com-pravin-pp-log4j2-CVE-2021-45105-1
nomisec
by dileepdkumar · poc
https://github.com/dileepdkumar/https-github.com-dileepdkumar-https-github.com-pravin-pp-log4j2-CVE-2021-45105-v
nomisec
by dileepdkumar · poc
https://github.com/dileepdkumar/https-github.com-dileepdkumar-https-github.com-pravin-pp-log4j2-CVE-2021-45105
nomisec
by dileepdkumar · poc
https://github.com/dileepdkumar/https-github.com-pravin-pp-log4j2-CVE-2021-45105
References (13)
Scores
CVSS v3
5.9
EPSS
0.7043
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
VulnCheck KEV
2021-12-22
Ransomware Use
Confirmed
CWE
CWE-674
CWE-20
Status
published
Products (50)
apache/log4j
2.0 - 2.3.1
debian/debian_linux
10.0
debian/debian_linux
11.0
netapp/cloud_manager
oracle/agile_engineering_data_management
6.2.1.0
oracle/agile_plm
9.3.6
oracle/agile_plm_mcad_connector
3.6
oracle/autovue_for_agile_product_lifecycle_management
21.0.2
oracle/banking_deposits_and_lines_of_credit_servicing
2.12.0
oracle/banking_enterprise_default_management
2.7.1
... and 40 more
Published
Dec 18, 2021
Tracked Since
Feb 18, 2026