Skip to content
COOEY

EXPOSURES › CVE-2021-45046

CVE-2021-45046

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-45046 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Apache Log4j2's incomplete fix for CVE-2021-44228 left the Thread Context Lookup Pattern vulnerable to remote code execution in non-default configurations.

The incomplete patch for CVE-2021-44228 allowed remote code execution via the Thread Context Lookup Pattern, enabling attackers to deploy ransomware and exfiltrate data. DIB organizations must ensure all Log4j2 instances are patched to the latest version and monitor for exploitation attempts, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns.

Shame score — Apache failed to fully patch a known vulnerability, leaving a critical remote code execution flaw that was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in maintaining software security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.