REDLEGG BLOG

Critical Vulnerability Bulletin Update for Log4J

12/14/21 6:05 PM  |  by RedLegg Blog

LOG4J Remote Code Execution Vulnerability (Update)

Identifier: CVE-2021-44228 and CVE-2021-45046

Exploit or POC: YES.

Update:

https://nvd.nist.gov/vuln/detail/CVE-2021-44228https://nvd.nist.gov/vuln/detail/CVE-2021-45046 (Updated reference)

https://nvd.nist.gov/vuln/detail/CVE-2021-45046

Description: CVE-2021-44228 allows an attacker to remotely execute code on the widely used logging library (Log4j). Log4J, between versions 2.0 and 2.15.0 are all affected by CVE-2021-44228 . https://nvd.nist.gov/vuln/detail/CVE-2021-45046

Mitigation recommendation: The only current mitigation is patching LOG4J to version 2.16.0. NIST has determined previous mitigation methods were incomplete and are undergoing additional analysis.

Get Blog Updates

Related Articles

Log4j In-Depth 96bravo

Log4j In-Depth

About On December 9th, 2021, a severe vulnerability (CVE-2021-44228) was released for the widely utilized Apache Log4j ...
Critical Vulnerability Bulletin December 2021 96bravo

Critical Vulnerability Bulletin December 2021

LOG4J Remote Code Execution Vulnerability (Update) Identifier: CVE-2021-44228 and CVE-2021-45046 Exploit or POC: YES. ...
Critical Security Vulnerabilities Bulletin