CVE-2021-45105

MEDIUM EXPLOITED RANSOMWARE

Apache Log4j < 2.3.1 - Improper Input Validation

Title source: rule

Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Exploits (11)

nomisec WORKING POC 13 stars
by cckuailong · poc
https://github.com/cckuailong/Log4j_dos_CVE-2021-45105
nomisec WORKING POC 3 stars
by iAmSOScArEd · poc
https://github.com/iAmSOScArEd/log4j2_dos_exploit
nomisec WORKING POC 1 stars
by name · poc
https://github.com/name/log4j-remediation
nomisec NO CODE
by aajuvonen · poc
https://github.com/aajuvonen/CVE-2021-45105-demo
nomisec WORKING POC
by dileepdkumar · poc
https://github.com/dileepdkumar/https-github.com-pravin-pp-log4j2-CVE-2021-45105-1
nomisec WORKING POC
by tejas-nagchandi · poc
https://github.com/tejas-nagchandi/CVE-2021-45105
nomisec WORKING POC
by pravin-pp · poc
https://github.com/pravin-pp/log4j2-CVE-2021-45105
vulncheck_xdb WORKING POC
remote
https://github.com/BabooPan/Log4Shell-CVE-2021-44228-Demo

Scores

CVSS v3 5.9
EPSS 0.7043
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2021-12-22
Ransomware Use Confirmed
CWE
CWE-674 CWE-20
Status published
Products (50)
apache/log4j 2.0 - 2.3.1
debian/debian_linux 10.0
debian/debian_linux 11.0
netapp/cloud_manager
oracle/agile_engineering_data_management 6.2.1.0
oracle/agile_plm 9.3.6
oracle/agile_plm_mcad_connector 3.6
oracle/autovue_for_agile_product_lifecycle_management 21.0.2
oracle/banking_deposits_and_lines_of_credit_servicing 2.12.0
oracle/banking_enterprise_default_management 2.7.1
... and 40 more
Published Dec 18, 2021
Tracked Since Feb 18, 2026