Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade aws-kinesis-agent | Jul 4, 2022 | Dec 18, 2021 |
| Apache Log4j Core | — | Upgrade Apache Log4j Core to 2.3.1Upgrade Apache Log4j Core to 2.17Upgrade Apache Log4j Core to 2.12.3 | Dec 20, 2021 | Dec 17, 2021 |
| Apache Ofbiz | — | Upgrade Apache OFBiz to the latest version | Dec 23, 2024 | Dec 18, 2021 |
| Debian | — | Upgrade apache-log4j2 | Dec 20, 2021 | Dec 18, 2021 |
| Freebsd | — | Upgrade opensearch | Nov 4, 2022 | Dec 27, 2021 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Aug 26, 2022 | Dec 18, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 18, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Dec 18, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.13 or later | Sep 22, 2025 | Dec 11, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Dec 11, 2021 |
| Suse | — | Upgrade log4j-javadocUpgrade log4j-slf4jUpgrade log4jUpgrade log4j-jcl | Dec 21, 2021 | Dec 18, 2021 |
| Ubuntu | — | Upgrade liblog4j2-java | Dec 20, 2021 | Dec 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub