E22-co461
CVSS:
9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
False Positive:
f
Variants:
544
Year:
2021
Description
A JNDI Injection vulnerability exists in Apache Log4j version 2.0-beta9 to 2.15.0, excluding 2.12.2.
The vulnerability is due to improper handling of logged messages when the logging configuration uses a non-default Pattern Layout.
An attacker who can control an item in the MapMessage or StrucutredDataMessage can exploit this vulnerability by sending a crafted message to be logged by the target application, a remote unauthenticated attacker can cause denial of service or in certain configuration execute arbitrary code on the target system. This vulnerability is due to the incomplete fix for CVE-2021-44228.
*NOTE: This strike uses the local hostname check bypass method.
CVE
References
https://www.whitesourcesoftware.com/resources/blog/log4j-vulnerability-cve-2021-45046/