CVE-2021-45105
Essential information
- Published
- 18/12/2021 13:15
- Modified
- 29/05/2026 15:41
- Author
- The MITRE Corporation
- Creator
- The MITRE Corporation
- CVSS
- 4.3 (v2) 5.9 MEDIUM (v3.1)
- CISA KEV
- No
- CWE
- CWE-20
- CVSS vector
-
AV:N/AC:M/Au:N/C:N/I:N/A:PCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H—
CVSS metrics
- Access vector
- Network
- Access complexity
- Medium
- Authentication
- None
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- Partial
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- High
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Attack requirements
- —
- Privileges required
- —
- User interaction
- —
- Confidentiality (V)
- —
- Confidentiality (S)
- —
- Integrity (V)
- —
- Integrity (S)
- —
- Availability (V)
- —
- Availability (S)
- —
- Exploit maturity
- —
Description
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
NVD status
- NVD
- View on NVD