cbcvebase.
CVE-2021-45105
published 2021-12-18

CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This…

medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Affected

232 ranges· showing 25
VendorProductVersion rangeFixed in
apachelog4j>= 2.0 < 2.3.12.3.1
apachelog4j2.13.0 – 2.16.0
apachelog4j>= 2.4 < 2.12.32.12.3
apachelogging
apacheofbiz
apache_software_foundationapache_log4j2>= log4j-core < 2.17.02.17.0
debianapache-log4j2< apache-log4j2 2.17.0-1 (bookworm)apache-log4j2 2.17.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
oracleagile_engineering_data_management
oracleagile_plm
oracleagile_plm_mcad_connector
oracleautovue_for_agile_product_lifecycle_management
oraclebanking_deposits_and_lines_of_credit_servicing
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_loans_servicing
oraclebanking_party_management
oraclebanking_payments
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_trade_finance
oraclebanking_treasury_management
oraclebusiness_intelligence

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck5.9MEDIUM