EXPOSURES › CVE-2021-45046
CVE-2021-45046
CRITICAL ⌖ ON CISA KEV · EXPLOITEDApache Log4j2's incomplete fix for CVE-2021-44228 left the Thread Context Lookup Pattern vulnerable to remote code execution in non-default configurations.
The incomplete patch for CVE-2021-44228 allowed remote code execution via the Thread Context Lookup Pattern, enabling attackers to deploy ransomware and exfiltrate data. DIB organizations must ensure all Log4j2 instances are patched to the latest version and monitor for exploitation attempts, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns.
Shame score — Apache failed to fully patch a known vulnerability, leaving a critical remote code execution flaw that was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in maintaining software security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.