← Back to CVE List
Vulnerability Intelligence Report
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

CVE-2021-45046

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:99.98%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-917 ↗CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache Log4j Apache Log4j2 < 2.16.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.977%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2021-12-14T00:00:00
Published2021-12-14T16:55:09
Last Updated2025-10-21T23:25:22

LINK COPIED TO CLIPBOARD