It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade java-11-openjdk-demo-debugUpgrade java-17-amazon-correttoUpgrade java-11-openjdk-static-libsUpgrade java-11-openjdk-headlessUpgrade java-1.8.0-amazon-corretto-develUpgrade java-11-openjdk-javadoc-zipUpgrade java-17-amazon-corretto-javadocUpgrade java-1.8.0-openjdkUpgrade java-1.7.0-openjdk-headlessUpgrade java-11-openjdk-src-debugUpgrade java-17-amazon-corretto-jmodsUpgrade java-11-openjdk-jmods-debugUpgrade java-11-openjdk-srcUpgrade java-1.8.0-amazon-correttoUpgrade java-17-amazon-corretto-headlessUpgrade java-11-openjdk-javadocUpgrade aws-kinesis-agentUpgrade java-11-openjdk-javadoc-debugUpgrade java-1.7.0-openjdk-javadocUpgrade java-11-openjdk-jmodsUpgrade java-11-openjdk-develUpgrade java-1.8.0-openjdk-headless-debugUpgrade java-11-amazon-corretto-headlessUpgrade java-17-amazon-corretto-develUpgrade java-1.7.0-openjdk-accessibilityUpgrade java-1.8.0-openjdk-srcUpgrade java-1.7.0-openjdkUpgrade java-1.8.0-openjdk-headlessUpgrade java-1.8.0-openjdk-javadoc-zip-debugUpgrade java-1.8.0-openjdk-develUpgrade java-11-openjdk-devel-debugUpgrade java-1.8.0-openjdk-javadocUpgrade java-11-openjdk-static-libs-debugUpgrade java-1.7.0-openjdk-demoUpgrade java-11-openjdk-debuginfoUpgrade java-1.8.0-openjdk-debuginfoUpgrade java-1.8.0-openjdk-accessibility-debugUpgrade java-1.8.0-openjdk-debugUpgrade java-1.7.0-openjdk-develUpgrade java-1.8.0-openjdk-devel-debugUpgrade java-1.8.0-openjdk-accessibilityUpgrade java-11-amazon-correttoUpgrade java-11-openjdk-javadoc-zip-debugUpgrade java-1.8.0-openjdk-demoUpgrade java-1.8.0-openjdk-demo-debugUpgrade java-1.8.0-openjdk-javadoc-zipUpgrade java-1.8.0-openjdk-src-debugUpgrade java-11-openjdk-headless-debugUpgrade java-1.7.0-openjdk-srcUpgrade java-11-openjdk-demoUpgrade java-11-amazon-corretto-javadocUpgrade java-1.7.0-openjdk-debuginfoUpgrade java-1.8.0-openjdk-javadoc-debugUpgrade java-11-openjdkUpgrade java-11-openjdk-debug | Jul 4, 2022 | Dec 14, 2021 |
| Amazon_linux | — | Upgrade java-1.6.0-openjdkUpgrade java-1.8.0-openjdkUpgrade java-1.7.0-openjdk | Dec 18, 2021 | Dec 14, 2021 |
| Apache Log4j Core | — | Upgrade Apache Log4j Core to 2.16Upgrade Apache Log4j Core to 2.12.2Upgrade Apache Log4j Core to 2.3.1 | Dec 14, 2021 | Dec 14, 2021 |
| Debian | — | Upgrade apache-log4j2 | Dec 17, 2021 | Dec 14, 2021 |
| Freebsd | — | Upgrade graylogUpgrade opensearch | Nov 4, 2022 | Dec 27, 2021 |
| Gentoo Linux | — | Upgrade net-wireless/unifi. | Oct 27, 2023 | Dec 14, 2021 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Aug 26, 2022 | Dec 14, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 14, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Dec 14, 2021 |
| Sonicwall Email Security | — | Update SonicWall Email Security to version 10.0.13 or later | Sep 22, 2025 | Dec 11, 2021 |
| Sonicwall Email Security Appliances | — | — | Sep 4, 2025 | Dec 11, 2021 |
| Suse | — | Upgrade log4j-slf4jUpgrade jakarta-servletUpgrade disruptor-javadocUpgrade jakarta-servlet-javadocUpgrade disruptorUpgrade log4j-jclUpgrade log4j-javadocUpgrade log4j | Dec 16, 2021 | Dec 14, 2021 |
| Ubuntu | — | Upgrade liblog4j2-java | Dec 16, 2021 | Dec 14, 2021 |
| Vcenter Log4j | — | Upgrade to non vulnerable version of vCenter when available, or implement mitigation measures as detailed by VMware in KB87081 | Feb 4, 2022 | Jan 7, 2022 |
| Vmsa 2021 0028 | — | Upgrade to VMware Workspace ONE Access version 21.08.0.0.18530336Upgrade to VMware Workspace ONE Access version 20.10.0.1.17586971Upgrade to VMware Workspace ONE Access version 20.10.0.0.17035009Upgrade to VMware Workspace ONE Access version 21.08.0.1.19010796 | Jan 4, 2022 | Jan 4, 2022 |
| Vmware Horizon Agent | — | Upgrade VMware Horizon Agent to 7.13.1.19066964Upgrade VMware Horizon Agent to 7.13.1.19067315Upgrade VMware Horizon Agent to 8.4.0.18964730Upgrade VMware Horizon Agent to 8.4.0.19050247Upgrade VMware Horizon Agent to 7.10.3.19069158Upgrade VMware Horizon Agent to 7.13.0.19067039Upgrade VMware Horizon Agent to 7.10.3.19066964 | Feb 9, 2022 | Dec 14, 2021 |
| Vmware Horizon Connection Server | — | Upgrade VMware Horizon Connection Server to 7.13.1.19069458Upgrade VMware Horizon Connection Server to 8.4.0.19067837Upgrade VMware Horizon Connection Server to 7.10.3.19069415 | Feb 1, 2022 | Dec 14, 2021 |
| Vmware Vrealize | — | Upgrade vRealize to version 8.6.2.19081814 | Jan 4, 2022 | Jan 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub