Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Vulnerability Description
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-45105
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Independently discovered by Hideki Okamoto of Akamai Technologies, Guy Lederfein of Trend Micro Research working with Trend Micro’s Zero Day Initiative, and another anonymous vulnerability researcher
References
- https://logging.apache.org/log4j/2.x/security.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
- https://www.kb.cert.org/vuls/id/930724
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
- http://www.openwall.com/lists/oss-security/2021/12/19/1
- https://www.debian.org/security/2021/dsa-5024
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
- https://security.netapp.com/advisory/ntap-20211218-0001/
- https://www.zerodayinitiative.com/advisories/ZDI-21-1541/
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdf
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →