CVE-2021-45105mediumobserved exploitationCWE-20CWE-674

CVE-2021-45105: medium-severity vulnerability in Apache Log4j2

Apache Log4j2 does not always protect from infinite recursion in lookup evaluation

Published · Updated

77Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 5.9epss 100%
from disclosure to weapon4 days
Published on NVDDec 18
1st PoC+4d
VulnCheck+4d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
4 products
Red Hat Decision Manager 7 · Red Hat Integration Camel Quarkus 1 · Red Hat OpenShift Container Platform 3.11 · streams for Apache Kafka
workaround: For Log4j 2 versions up to and including 2.16.0, this flaw can be mitigated by: - In PatternLayout in the Log4j logging configuration, replace Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc…
Fixed
17 products (33 components)
OpenShift Logging 5.0 · OpenShift Logging 5.1 · OpenShift Logging 5.2 · OpenShift Logging 5.3 · Red Hat OpenShift Container Platform 4.6 · and others 12
Not affected
20 products (2,369 components) — because the vulnerable code is not present in the product
Red Hat JBoss Enterprise Application Platform · Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · OpenShift Logging 5.2 · OpenShift Logging 5.3 · and others 15
In short

Apache Log4j2 versions before 2.17.0 are vulnerable to infinite recursion when processing specially crafted lookup strings in thread context data. An attacker who can control this data can crash the application, causing denial of service.

Technical detail

The vulnerability exists in Log4j2's lookup evaluation mechanism (CWE-674: uncontrolled recursion; CWE-20: improper input validation), where self-referential lookups are not properly restricted. An attacker with write access to Thread Context Map can supply a malicious string that triggers recursive evaluation, exhausting stack memory and terminating the affected process.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.