CISA Known Exploited Vulnerability

CVE-2021-45046 Ransomware

Apache · Log4j2

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Date added
BOD 22-01 due date
CWE CWE-917
Ransomware Known

CISA description

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Required action

Apply updates per vendor instructions.