CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Published Dec 14, 2021
·
Updated

Impact

The fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack.

Affected packages Only the org.apache.logging.log4j:log4j-core package is directly affected by this vulnerability. The org.apache.logging.log4j:log4j-api should be kept at the same version as the org.apache.logging.log4j:log4j-core package to ensure compatability if in use.

Mitigation

Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. This issue can be mitigated in prior releases (< 2.16.0) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-.jar org/apache/logging/log4j/core/lookup/JndiLookup.class).

Log4j 2.15.0 restricts JNDI LDAP lookups to localhost by default. Note that previous mitigations involving configuration such as to set the system property log4j2.formatMsgNoLookups to true do NOT mitigate this specific vulnerability.

Other sources

A flaw was found in the Apache Log4j logging library in versions from 2.0.0 and before 2.16.0. A remote attacker with control over Thread Context Map (MDC) input data could craft malicious input using a JNDI Lookup pattern resulting in remote code execution (RCE) in a limited number of environments.

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

CISA

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 restricts JNDI LDAP lookups to localhost by default. Note that previous mitigations involving configuration such as to set the system property log4j2.noFormatMsgLookup to true do NOT mitigate this specific vulnerability.

Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

This issue can be mitigated in prior releases (<2.16.0) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-.jar org/apache/logging/log4j/core/lookup/JndiLookup.class).

Reference: https://www.openwall.com/lists/oss-security/2021/12/14/4

Red Hat

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Affected Software

121 affected componentsFixes available
debian/apache-log4j2
2.17.1-1~deb10u12.17.0-1~deb10u12.17.1-1~deb11u12.17.0-1~deb11u12.19.0-2
debian/apache-log4j2<=2.15.0-1, <=2.15.0-1~deb10u1, <=2.15.0-1~deb11u1
2.16.0-12.16.0-1~deb11u12.16.0-1~deb10u1
redhat/eap7-log4j<0:2.17.1-1.redhat_00001.1.el8ea
0:2.17.1-1.redhat_00001.1.el8ea
redhat/eap7-log4j<0:2.17.1-1.redhat_00001.1.el7ea
0:2.17.1-1.redhat_00001.1.el7ea
Apache Log4j2
redhat/log4j<2.16.0
2.16.0
Apache Log4j>=2.0.1<2.12.2
Apache Log4j>=2.13.0<2.16.0
Apache Log4j=2.0
Apache Log4j=2.0-beta9
Apache Log4j=2.0-rc1
Apache Log4j=2.0-rc2
Intel Audio Development Kit
Intel Computer Vision Annotation Tool
Intel Datacenter Manager
Intel Genomics Kernel Library
Intel Oneapi Eclipse
Intel Secure Device Onboard
Intel Sensor Solution Firmware Development Kit
Intel System Debugger
Intel System Studio
Siemens Sppa-t3000 Ses3000 Firmware
Siemens Sppa-t3000 Ses3000
Siemens Captial<2019.1
Siemens Captial=2019.1
Siemens Captial=2019.1-sp1912
Siemens COMOS
Siemens Desigo Cc Advanced Reports=4.0
Siemens Desigo Cc Advanced Reports=4.1
Siemens Desigo Cc Advanced Reports=4.2
Siemens Desigo Cc Advanced Reports=5.0
Siemens Desigo Cc Advanced Reports=5.1
Siemens Desigo Cc Info Center=5.0
Siemens Desigo Cc Info Center=5.1
Siemens E-car Operation Center<2021-12-13
Siemens Energy Engage=3.1
Siemens Energyip=8.5
Siemens Energyip=8.6
Siemens Energyip=8.7
Siemens Energyip=9.0
Siemens Energyip Prepay=3.7
Siemens Energyip Prepay=3.8
Siemens Gma-manager<8.6.2j-398
Siemens Head-end System Universal Device Integration System
Siemens Industrial Edge Management
Siemens Industrial Edge Management Hub<2021-12-13
Siemens Logo\! Soft Comfort
Siemens Mendix
Siemens Mindsphere<2021-12-11
Siemens Navigator<2021-12-13
Siemens Nx
Siemens Opcenter Intelligence<=3.2
Siemens Operation Scheduler<=1.1.3
Siemens Sentron Powermanager=4.1
Siemens Sentron Powermanager=4.2
Siemens Siguard Dsa=4.2
Siemens Siguard Dsa=4.3
Siemens Siguard Dsa=4.4
Siemens SiPass integrated=2.80
Siemens SiPass integrated=2.85
Siemens Siveillance Command<=4.16.2.1
Siemens Siveillance Control Pro
Siemens Siveillance Identity=1.5
Siemens Siveillance Identity=1.6
Siemens Siveillance Vantage
Siemens Siveillance Viewpoint
Siemens Solid Edge Cam Pro
Siemens Solid Edge Harness Design<2020
Siemens Solid Edge Harness Design=2020
Siemens Solid Edge Harness Design=2020
Siemens Solid Edge Harness Design=2020-sp2002
Siemens Spectrum Power 4<4.70
Siemens Spectrum Power 4=4.70
Siemens Spectrum Power 4=4.70-sp7
Siemens Spectrum Power 4=4.70-sp8
Siemens Spectrum Power 7<2.30
Siemens Spectrum Power 7=2.30
Siemens Spectrum Power 7=2.30
Siemens Spectrum Power 7=2.30-sp2
Siemens Teamcenter
Siemens Tracealertserverplus
Siemens Vesys<2019.1
Siemens Vesys=2019.1
Siemens Vesys=2019.1
Siemens Vesys=2019.1-sp1912
Siemens Xpedition Enterprise
Siemens Xpedition Package Integrator
Debian Debian Linux=10.0
Debian Debian Linux=11.0
SonicWall Email Security<10.0.12
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Siemens 6bk1602-0aa12-0tp0 Firmware<2.7.0
Siemens 6bk1602-0aa12-0tp0
Siemens 6bk1602-0aa22-0tp0 Firmware<2.7.0
Siemens 6bk1602-0aa22-0tp0
Siemens 6bk1602-0aa32-0tp0 Firmware<2.7.0
Siemens 6bk1602-0aa32-0tp0
Siemens 6bk1602-0aa42-0tp0 Firmware<2.7.0
Siemens 6bk1602-0aa42-0tp0
Siemens 6bk1602-0aa52-0tp0 Firmware<2.7.0
Siemens 6bk1602-0aa52-0tp0
CVAT Computer Vision Annotation Tool
All of the following
Siemens Sppa-t3000 Ses3000 Firmware
Siemens Sppa-t3000 Ses3000
All of the following
Siemens 6bk1602-0aa12-0tp0
Siemens 6bk1602-0aa12-0tp0 Firmware<2.7.0
All of the following
Siemens 6bk1602-0aa22-0tp0
Siemens 6bk1602-0aa22-0tp0 Firmware<2.7.0
All of the following
Siemens 6bk1602-0aa32-0tp0
Siemens 6bk1602-0aa32-0tp0 Firmware<2.7.0
All of the following
Siemens 6bk1602-0aa42-0tp0
Siemens 6bk1602-0aa42-0tp0 Firmware<2.7.0
All of the following
Siemens 6bk1602-0aa52-0tp0
Siemens 6bk1602-0aa52-0tp0 Firmware<2.7.0
maven/org.ops4j.pax.logging:pax-logging-log4j2>=2.0.0<2.0.12
2.0.12
maven/org.ops4j.pax.logging:pax-logging-log4j2>=1.11.0<1.11.11
1.11.11
maven/org.ops4j.pax.logging:pax-logging-log4j2>=1.10.0<1.10.8
1.10.8
maven/org.ops4j.pax.logging:pax-logging-log4j2>=1.8.0<1.9.2
1.9.2
maven/org.apache.logging.log4j:log4j-core<2.12.2
2.12.2
maven/org.apache.logging.log4j:log4j-core>=2.13.0<2.16.0
2.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.16.0-1Fixed in 2.16.0-1~deb11u1Fixed in 2.16.0-1~deb10u1
  2. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.17.1-1~deb10u1Fixed in 2.17.0-1~deb10u1Fixed in 2.17.1-1~deb11u1Fixed in 2.17.0-1~deb11u1Fixed in 2.19.0-2
  3. Upgrade

    Upgrade redhat/eap7-log4j to a version that resolves this vulnerability.

    Fixed in 0:2.17.1-1.redhat_00001.1.el8ea
  4. Upgrade

    Upgrade redhat/eap7-log4j to a version that resolves this vulnerability.

    Fixed in 0:2.17.1-1.redhat_00001.1.el7ea
  5. Upgrade

    Upgrade maven/org.ops4j.pax.logging:pax-logging-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.0.12
  6. Upgrade

    Upgrade maven/org.ops4j.pax.logging:pax-logging-log4j2 to a version that resolves this vulnerability.

    Fixed in 1.11.11
  7. Upgrade

    Upgrade maven/org.ops4j.pax.logging:pax-logging-log4j2 to a version that resolves this vulnerability.

    Fixed in 1.10.8
  8. Upgrade

    Upgrade maven/org.ops4j.pax.logging:pax-logging-log4j2 to a version that resolves this vulnerability.

    Fixed in 1.9.2
  9. Upgrade

    Upgrade maven/org.apache.logging.log4j:log4j-core to a version that resolves this vulnerability.

    Fixed in 2.12.2
  10. Upgrade

    Upgrade maven/org.apache.logging.log4j:log4j-core to a version that resolves this vulnerability.

    Fixed in 2.16.0
  11. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 2.16.0
  12. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.16.0-1
  13. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.16.0-1~deb11u1
  14. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.16.0-1~deb10u1
  15. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.17.1-1~deb10u1
  16. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.17.0-1~deb10u1
  17. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.17.1-1~deb11u1
  18. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.17.0-1~deb11u1
  19. Upgrade

    Upgrade debian/apache-log4j2 to a version that resolves this vulnerability.

    Fixed in 2.19.0-2
  20. Configuration

    For Log4j versions up to and including 2.15.0, remove the JndiLookup class from the classpath to mitigate the issue. Example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class

    org.apache.logging.log4j:log4j-core JndiLookup class = removed
  21. Configuration

    Keep org.apache.logging.log4j:log4j-api at the same version as org.apache.logging.log4j:log4j-core to ensure compatibility (set the API dependency version to the same fixed_version used for log4j-core).

    org.apache.logging.log4j:log4j-api version = match log4j-core version

Event History

Dec 14, 2021
CVE Published
12:00 AM
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionWeakness
Advisory Published
via GitHub·06:01 PM
Data Sourced
via Red Hat·06:30 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 1, 2023
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the impact of CVE-2021-45046?

The impact of CVE-2021-45046 is critical, with a severity value of 9. It could allow attackers with control over Thread Context Map (MDC) input data to execute arbitrary code.

2

What is the affected software for CVE-2021-45046?

The affected software includes Apache Log4j2 versions prior to 2.17.1 and certain versions of eap7-log4j, log4j, and org.apache.logging.log4j:log4j-core.

3

How can I fix CVE-2021-45046?

To fix CVE-2021-45046, update Apache Log4j2 to version 2.17.1 or newer. If using eap7-log4j, log4j, or org.apache.logging.log4j:log4j-core, update to the recommended versions provided by the respective vendors.

4

Where can I find more information about CVE-2021-45046?

You can find more information about CVE-2021-45046 on the Apache Log4j website, CVE website, NIST National Vulnerability Database, Red Hat Security Advisories, and the Openwall mailing list.

5

What are the CWEs associated with CVE-2021-45046?

The CWEs associated with CVE-2021-45046 are CWE-20, CWE-502, CWE-400, and CWE-917.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203