← voltar
CVE-2021-4104highexploração observadaCWE-502

Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2

65Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Actcvss 7.5epss 81%
da publicação à arma
Publicada no NVD14 de dez.
VulnCheck+133d
probabilidade de exploração
81%top 1% das CVEs
exploração observada
simVulnCheck
O que os fabricantes declaram (VEX)

Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.

Afetado
6 produtos (7 componentes)
Red Hat OpenStack Platform 13 (Queens) · A-MQ Clients 2 · Red Hat AMQ Broker 7 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · e outros 1
workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JMSAppender in the Log4j configuration if it is used - Remove the JMSAppender class from the classpath…
Corrigido
56 produtos (579 componentes)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Web Server 3.1 for RHEL 7 · RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 · e outros 51
Não afetado
19 produtos (2.282 componentes)porque o código vulnerável não está presente no produto
Red Hat JBoss Enterprise Application Platform · Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · Red Hat Enterprise Linux 7 · e outros 14
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H