cbcvebase.
CVE-2021-45046
published 2022-08-24

CVE-2021-45046: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all…

PriorityP198critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-05-22
Exploited in the wild
EPSS
99.98%
100.0th percentile
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.

Affected

83 ranges· showing 25
VendorProductVersion rangeFixed in
amazonhotpatch< 1.3.51.3.5
apachelog4j
apachelog4j>= 2.0.1 < 2.12.22.12.2
apachelog4j>= 2.13.0 < 2.16.02.16.0
apachelogging
debianapache-log4j2< apache-log4j2 2.16.0-1 (bookworm)apache-log4j2 2.16.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
kube-reportinghive
paloaltobridgecrew
paloaltocortex_data_lake
paloaltocortex_xdr_agent
paloaltocortex_xpanse
paloaltocortex_xsoar
paloaltoenterprise_data_loss_prevention
paloaltoexact_data_matching_cli
paloaltoexpedition
paloaltoglobalprotect_app
paloaltoiot_security
paloaltookyo_garde
paloaltopan-db_private_cloud
paloaltopan-os
paloaltoprisma_access

Detection & IOCsextracted from sources · hover to see the quote

  • Detect vulnerable log4j jar versions at or below 2.15 in running containers and container images using Qualys QID 376178 for CVE-2021-45046
  • Use the following QQL query in Qualys Container Security to identify containers and images impacted by CVE-2021-45046 (among other Log4Shell CVEs)
  • Setting log4j2.noFormatMsgLookup to true does NOT mitigate CVE-2021-45046; detection/response should not rely on this flag as a bypass indicator
  • CVE-2021-45046 was introduced in Log4j2 version 2.15.0; hunt for environments still running this specific version as they remain vulnerable
  • Threat actors are observed using payloads incorporating key extraction attempts and base64 encoded payloads when exploiting CVE-2021-45046; hunt for base64-encoded JNDI strings in HTTP headers and log inputs
  • Conti ransomware affiliates exploited CVE-2021-45046 (Log4Shell) on vulnerable VMware Horizon servers; monitor VMware Horizon for JNDI-based exploitation attempts and subsequent Cobalt Strike beaconing
  • Post-exploitation indicators following CVE-2021-45046 exploitation include: Cobalt Strike beaconing, AnyDesk installation, IPC$ share access, RDP lateral movement, local admin account creation, and Windows Vault credential access
  • Incomplete remediation of CVE-2021-45046 in OpenShift Metering hive containers (versions 4.6, 4.7, 4.8) was due to not all JndiLookup.class files being removed; verify removal of ALL JndiLookup.class instances from log4j-core jars as a detection/validation step
  • Alternative lookup code paths exist beyond Thread Context attack vector; monitor for Logger.printf with user-controlled input and custom message factory usage as potential CVE-2021-45046 exploitation vectors
  • ·CVE-2021-45046 was re-scored from CVSS 3.7 to 9.0 after limited RCE was confirmed; initial assessments based on the lower score underestimate the risk
  • ·The formatMsgNoLookups=true setting (default in 2.15.0) does NOT fully mitigate CVE-2021-45046 due to alternative lookup paths; upgrading to a safe version or removing JndiLookup class is required
  • ·OpenShift Metering hive containers in versions 4.6, 4.7, and 4.8 may still be vulnerable even after applying the original Log4Shell patch, as not all JndiLookup.class files were removed

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_apache9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.