Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Dec 24, 2021

High
CISA KEVRansomware

CVE-2021-44228

ApacheLog4j2

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Known
Published
Dec 10, 2021
KEV Added
Dec 10, 2021
Due Date
Dec 24, 2021
Related Articles
0

Vendor

Apache

Log4j2