CVE-2021-45105: medium-severity vulnerability in Apache Log4j2
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published · Updated
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apache Log4j2 versions before 2.17.0 are vulnerable to infinite recursion when processing specially crafted lookup strings in thread context data. An attacker who can control this data can crash the application, causing denial of service.
The vulnerability exists in Log4j2's lookup evaluation mechanism (CWE-674: uncontrolled recursion; CWE-20: improper input validation), where self-referential lookups are not properly restricted. An attacker with write access to Thread Context Map can supply a malicious string that triggers recursive evaluation, exhausting stack memory and terminating the affected process.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.