All vulnerabilities
CRITICALInfraexploited in the wildransomware

CVE-2021-44228

Apache · Apache Log4j 2 (log4j-core)

Summary

Apache Log4j 2 performs JNDI lookups on attacker-controllable log message content without restricting protocols. An attacker who gets a crafted string such as ${jndi:ldap://...} logged causes the server to fetch and execute arbitrary code from a remote LDAP/RMI server, yielding full unauthenticated remote code execution. Because logging user-supplied input is ubiquitous, it affected millions of Java applications and devices worldwide. Within hours of disclosure attackers mass-scanned the internet to drop coin miners, Cobalt Strike, and ransomware.

References

Related vulnerabilities

All Infra →