CVE-2021-44228

Source
https://cve.org/CVERecord?id=CVE-2021-44228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-44228
Aliases
Downstream
Related
Published
2021-12-10T10:15:09.143Z
Modified
2026-02-05T21:40:15.497027Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

References

Affected packages

Git / github.com/schema-inspector/schema-inspector

Affected ranges

Type
GIT
Repo
https://github.com/schema-inspector/schema-inspector
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed

Affected versions

1.*
1.7.0
2.*
2.0.0
v1.*
v1.4.6
v1.4.7
v1.4.8
v1.6.10
v1.6.7
v1.6.8
v1.6.9
v2.*
v2.0.1
v2.0.2
v2.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44228.json"

Git / github.com/squid-cache/squid

Affected versions

Other
BASIC_TPROXY4
HISTORIC_RELEASES
SQUID_3_0_PRE1
SQUID_3_0_PRE2
SQUID_3_0_PRE3
SQUID_3_0_PRE4
SQUID_3_0_PRE5
SQUID_3_0_PRE6
SQUID_3_0_PRE7
SQUID_3_0_RC1
SQUID_3_2_0_1
SQUID_3_2_0_10
SQUID_3_2_0_11
SQUID_3_2_0_12
SQUID_3_2_0_13
SQUID_3_2_0_14
SQUID_3_2_0_15
SQUID_3_2_0_16
SQUID_3_2_0_17
SQUID_3_2_0_18
SQUID_3_2_0_19
SQUID_3_2_0_2
SQUID_3_2_0_3
SQUID_3_2_0_4
SQUID_3_2_0_5
SQUID_3_2_0_6
SQUID_3_2_0_7
SQUID_3_2_0_8
SQUID_3_2_0_9
SQUID_3_4_0_1
SQUID_3_4_0_2
SQUID_3_4_0_3
SQUID_3_4_1
SQUID_3_4_2
SQUID_3_4_3
SQUID_3_5_0_1
SQUID_3_5_0_2
SQUID_3_5_0_3
SQUID_3_5_0_4
SQUID_3_5_1
SQUID_3_5_2
SQUID_3_5_3
for-libecap-v0p1
merge-candidate-3-v1
merge-candidate-3-v2
sourceformat-review-1
take00
take01
take02
take03
take04
take06
take07
take08
take09
take1
take2
BumpSslServerFirst.*
BumpSslServerFirst.take01
BumpSslServerFirst.take02
BumpSslServerFirst.take03
BumpSslServerFirst.take04
BumpSslServerFirst.take05
BumpSslServerFirst.take06
BumpSslServerFirst.take07
BumpSslServerFirst.take08
BumpSslServerFirst.take09
BumpSslServerFirst.take10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44228.json"