CVE-2021-45105 is a denial-of-service vulnerability affecting Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1), impacting products from vendors like Apache, Debian, and Oracle. An attacker can trigger uncontrolled recursion via self-referential lookups with crafted Thread Context Map data, leading to a system crash. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high attack complexity, resulting in a high impact on availability. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.3.1CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
>= 2.4, < 2.12.3CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
>= 2.13.0, <= 2.16.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Dec 18, 2021log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
Dec 18, 2021SPS Apache Log4j Vulnerability
Dec 16, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021