CVE-2021-45046 is an incomplete fix for CVE-2021-44228 in Apache Log4j 2.15.0, allowing attackers to craft malicious input via Thread Context Map (MDC) when specific non-default Pattern Layouts are used, leading to information leakage, remote code execution, or local code execution. This critical vulnerability (CVSS 9.0) affects numerous products including Apache, Debian, and Intel, and has a high FAUCET Risk Score of 100/100. It is actively exploited in the wild, including in known ransomware campaigns, with Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.1, < 2.12.2CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
>= 2.13.0, < 2.16.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021HBT Apache Log4j Vulnerability
Dec 16, 2021SPS Apache Log4j Vulnerability
Dec 16, 2021AS-2021-001: Log4Shell (Log4j 2)
Dec 16, 2021Incomplete fix for Apache Log4j vulnerability
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021NR21-04
Dec 13, 2021NR21-03
Dec 10, 2021NR21-03
Dec 10, 2021