← volver
CVE-2021-4104highexplotación observadaCWE-502

Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2

65Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Actcvss 7.5epss 81%
de la publicación al arma
Publicada en NVD14 dic
VulnCheck+133d
probabilidad de explotación
81%top 1% de las CVE
explotación observada
VulnCheck
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
6 productos (7 componentes)
Red Hat OpenStack Platform 13 (Queens) · A-MQ Clients 2 · Red Hat AMQ Broker 7 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · y otros 1
workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath…
Corregido
56 productos (579 componentes)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Web Server 3.1 for RHEL 7 · RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 · y otros 51
No afectado
19 productos (2282 componentes)porque el código vulnerable no está presente en el producto
Red Hat JBoss Enterprise Application Platform · Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · Red Hat Enterprise Linux 7 · y otros 14
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H