CVE-2021-44228 — Apache Log4j2 Remote Code Execution Vulnerability
2021-12-10 • CISA Known Exploited Vulnerability
[event] Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Apache |
| Product | Log4j2 |
| CWE | CWE-20, CWE-400, CWE-502 |
| CVE ID | CVE-2021-44228 |
| Date Added | 2021-12-10 |
| Due Date | 2021-12-24 |
| Ransomware Campaign | Known — this vulnerability has been leveraged in ransomware campaigns |
> MITIGATION
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Due Date: 2021-12-24