It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade java-11-amazon-correttoUpgrade java-11-openjdk-javadoc-zip-debugUpgrade java-11-openjdk-debuginfoUpgrade java-1.7.0-openjdk-develUpgrade java-1.8.0-openjdk-debuginfoUpgrade java-1.7.0-openjdk-debuginfoUpgrade java-1.8.0-openjdk-javadoc-zipUpgrade java-11-openjdk-debugUpgrade java-1.8.0-openjdk-devel-debugUpgrade java-1.8.0-openjdk-accessibility-debugUpgrade java-11-openjdk-demoUpgrade java-1.8.0-openjdk-demoUpgrade java-1.8.0-openjdk-demo-debugUpgrade java-1.7.0-openjdk-srcUpgrade java-11-openjdk-headless-debugUpgrade java-1.8.0-openjdk-debugUpgrade java-11-amazon-corretto-javadocUpgrade java-1.8.0-openjdk-javadoc-debugUpgrade java-11-openjdkUpgrade java-1.8.0-openjdk-accessibilityUpgrade java-1.8.0-openjdk-src-debugUpgrade java-17-amazon-correttoUpgrade java-11-openjdk-demo-debugUpgrade java-1.8.0-openjdk-develUpgrade java-1.8.0-openjdkUpgrade java-11-openjdk-src-debugUpgrade java-1.8.0-amazon-corretto-develUpgrade java-1.8.0-amazon-correttoUpgrade java-11-openjdk-jmodsUpgrade java-11-openjdk-headlessUpgrade java-17-amazon-corretto-javadocUpgrade java-17-amazon-corretto-develUpgrade java-11-openjdk-javadoc-debugUpgrade java-1.7.0-openjdk-accessibilityUpgrade java-11-amazon-corretto-headlessUpgrade java-11-openjdk-srcUpgrade java-1.8.0-openjdk-srcUpgrade aws-kinesis-agentUpgrade java-11-openjdk-develUpgrade java-1.8.0-openjdk-headlessUpgrade java-11-openjdk-static-libsUpgrade java-1.7.0-openjdk-javadocUpgrade java-1.7.0-openjdkUpgrade java-11-openjdk-javadoc-zipUpgrade java-1.8.0-openjdk-headless-debugUpgrade java-17-amazon-corretto-headlessUpgrade java-11-openjdk-javadocUpgrade java-1.7.0-openjdk-headlessUpgrade java-11-openjdk-jmods-debugUpgrade java-11-openjdk-devel-debugUpgrade java-1.8.0-openjdk-javadoc-zip-debugUpgrade java-11-openjdk-static-libs-debugUpgrade java-1.8.0-openjdk-javadocUpgrade java-1.7.0-openjdk-demoUpgrade java-17-amazon-corretto-jmods | Jul 4, 2022 | Dec 14, 2021 |
| Amazon_linux | — | Upgrade java-1.6.0-openjdkUpgrade java-1.8.0-openjdkUpgrade java-1.7.0-openjdk | Dec 18, 2021 | Dec 14, 2021 |
| Apache Log4j Core | — | Upgrade Apache Log4j Core to 2.12.2Upgrade Apache Log4j Core to 2.16Upgrade Apache Log4j Core to 2.3.1 | Dec 14, 2021 | Dec 14, 2021 |
| Debian | — | Upgrade apache-log4j2 | Dec 17, 2021 | Dec 14, 2021 |
| Freebsd | — | Upgrade graylogUpgrade opensearch | Nov 4, 2022 | Dec 27, 2021 |
| Gentoo Linux | — | Upgrade net-wireless/unifi. | Oct 27, 2023 | Dec 14, 2021 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Aug 26, 2022 | Dec 14, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 14, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Dec 14, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.13 or later | Sep 22, 2025 | Dec 11, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Dec 11, 2021 |
| Suse | — | Upgrade log4j-javadocUpgrade log4j-jclUpgrade log4jUpgrade disruptorUpgrade log4j-slf4jUpgrade jakarta-servlet-javadocUpgrade disruptor-javadocUpgrade jakarta-servlet | Dec 16, 2021 | Dec 14, 2021 |
| Ubuntu | — | Upgrade liblog4j2-java | Dec 16, 2021 | Dec 14, 2021 |
| Vcenter Log4j | — | Upgrade to non vulnerable version of vCenter when available, or implement mitigation measures as detailed by VMware in KB87081 | Feb 4, 2022 | Jan 7, 2022 |
| Vmsa 2021 0028 | — | Upgrade to VMware Workspace ONE Access version 21.08.0.0.18530336Upgrade to VMware Workspace ONE Access version 20.10.0.1.17586971Upgrade to VMware Workspace ONE Access version 20.10.0.0.17035009Upgrade to VMware Workspace ONE Access version 21.08.0.1.19010796 | Jan 4, 2022 | Jan 4, 2022 |
| Vmware Horizon Agent | — | Upgrade VMware Horizon Agent to 8.4.0.19050247Upgrade VMware Horizon Agent to 7.13.0.19067039Upgrade VMware Horizon Agent to 7.10.3.19069158Upgrade VMware Horizon Agent to 8.4.0.18964730Upgrade VMware Horizon Agent to 7.13.1.19066964Upgrade VMware Horizon Agent to 7.13.1.19067315Upgrade VMware Horizon Agent to 7.10.3.19066964 | Feb 9, 2022 | Dec 14, 2021 |
| Vmware Horizon Connection Server | — | Upgrade VMware Horizon Connection Server to 7.13.1.19069458Upgrade VMware Horizon Connection Server to 8.4.0.19067837Upgrade VMware Horizon Connection Server to 7.10.3.19069415 | Feb 1, 2022 | Dec 14, 2021 |
| Vmware Vrealize | — | Upgrade vRealize to version 8.6.2.19081814 | Jan 4, 2022 | Jan 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub