Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 22, 2023

CVE-2021-45046

High
CVSS 9EPSS 94.3%CISA KEVRansomware
Apache/Log4j2

Description

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

CVSS Score

9/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS — Exploit Probability

94.3%

Higher than 100.0% of all CVEs

Weakness Classification (CWE)

CWE-917CWE-917MITRE

Required Action

https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046

Risk Assessment

CRITICAL
In CISA KEV
Critical CVSS
High EPSS
Ransomware

Details

Severity
High
CVSS
9
EPSS
94.3%
CWE
CWE-917
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

May 1, 2023

Added to KEV

May 1, 2023

Remediation Due

May 22, 2023

Affected Product

Apache

Log4j2

View all Apache CVEs