{"id":"CVE-2021-44228","aliases":["GHSA-jfh8-c2jp-5v3q"],"url":"https://o3.security/vulnerability/CVE-2021-44228","summary":"Remote code injection in Log4j","details":"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.","published":"2021-12-10T10:15:09.143Z","modified":"2026-08-13T04:01:09.237466383Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.99999,"percentile":1,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":384,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.logging.log4j:log4j-core","fixedVersion":"2.15.0"},{"ecosystem":"Maven","name":"org.apache.logging.log4j:log4j-core","fixedVersion":"2.3.1"},{"ecosystem":"Maven","name":"org.apache.logging.log4j:log4j-core","fixedVersion":"2.12.2"},{"ecosystem":"Maven","name":"com.guicedee.services:log4j-core","fixedVersion":null},{"ecosystem":"Maven","name":"org.xbib.elasticsearch:log4j","fixedVersion":null},{"ecosystem":"Maven","name":"uk.co.nichesolutions.logging.log4j:log4j-core","fixedVersion":null},{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"1.9.2"},{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"1.10.8"},{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"1.11.10"},{"ecosystem":"Maven","name":"org.ops4j.pax.logging:pax-logging-log4j2","fixedVersion":"2.0.11"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2022/Jul/11"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2022/Mar/23"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/10/1"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/10/2"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/10/3"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/13/1"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/13/2"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/14/4"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/12/15/3"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"},{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"},{"type":"ADVISORY","url":"https://github.com/cisagov/log4j-affected-db"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/"},{"type":"ADVISORY","url":"https://logging.apache.org/log4j/2.x/security.html"},{"type":"ADVISORY","url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20211210-0007/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT213189"},{"type":"ADVISORY","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"},{"type":"ADVISORY","url":"https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001"},{"type":"ADVISORY","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5020"},{"type":"ADVISORY","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"},{"type":"ADVISORY","url":"https://www.kb.cert.org/vuls/id/930724"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"},{"type":"FIX","url":"https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2022/Dec/2"},{"type":"EVIDENCE","url":"https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228"},{"type":"EVIDENCE","url":"https://twitter.com/kurtseifried/status/1469345530182455296"},{"type":"EVIDENCE","url":"https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T04:01:09.237466383Z"}}