CVE-2021-44228

critical

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

From the Tenable Blog

CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities

Published: 2021-12-17

A list of frequently asked questions related to Log4Shell and associated vulnerabilities.

CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)

Published: 2021-12-10

Critical vulnerability in the popular logging library, Log4j 2, impacts a number of services and applications, including Minecraft, Steam and Apple iCloud. Attackers have begun actively scanning for and attempting to exploit the flaw.

References

https://github.com/hed1ad/CVE-Omarchy-Plugin

https://github.com/AsadAliEngineer/RAG-Based-Threat-Intelligence-Assistant

https://github.com/KalidouLabghaly/log4shell-exploitation-detection

https://github.com/mwangie29/cve-atlas

https://github.com/4ttth/offline-cve-web

https://github.com/AsadAliEng/RAG-Based-Threat-Intelligence-Assistant

https://github.com/TayR-D/patchwork-cve

https://github.com/san3ncrypt3d/vulnometry

https://github.com/reshot2005/cve-lookup

https://github.com/MUGHEESM/sbom-sentinel

https://github.com/Vaibhav91one/log4shell-cve-lab

https://github.com/BogdanStamenovic/vsearch

https://github.com/dr-tharma/cve-insights-2.0

https://github.com/Sudo-Zaid/cve-poc-writeups

https://github.com/muhammedalakbarli/cvault

https://github.com/dr-tharma/mai-cve-insights

https://github.com/0xvanguard/vulnseeker

https://github.com/RenatoAntunovic/cve-metasploit-skeniranje

https://github.com/FarwaImtiaz-FI/soc-assistant

https://github.com/Balckers/mcp-security-server

https://github.com/PwnedBytes0x1/cveye

https://github.com/Yel1oww/n8n-Docker-CVE-Watch

https://github.com/sivabathina-egen/CVE_Remidiation_tool_test_data

https://github.com/superb24ED/cve_scanner

https://github.com/NoNFake/cve-cli

https://github.com/yt010108/CVEs

https://github.com/VOE9/cve-explain

https://github.com/jconig/cve-lookup

https://github.com/ChidiRepository/cve-intelligence-platform

https://github.com/BlAck9D/Curator

https://github.com/saaheerpurav/cve-twin

https://github.com/Induj1/cve-twin

https://github.com/lr-elaina520/cve-analysis

https://github.com/chengbochuan3/Security-Blog

https://github.com/AAH20/vuln-triage

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/chengbochuan3/CVE-Learn

https://github.com/berinle/spring-enterprise-remediation-demo

https://github.com/atoussec-ctrl/deep-recon

https://github.com/ahntenna/cvepass

https://github.com/anshumaan12-2003/trustflow

https://github.com/frankremmy/cve-detection-lab

https://github.com/AhndreWalters/ProjectSecurity-Homelab

https://github.com/Adolanium/hermes-plugin-shodan

https://github.com/RaajitSingh1306/ThreatMind

https://github.com/nkoziel/cve-to-detection-rule

https://github.com/Lek-glitch/cve-splunk-agent

https://github.com/Phanidhar007/vuln-auditor

https://github.com/yomymy/CVE-Vuln-Records

https://github.com/joshuaweiiii/CVE_Compass

https://github.com/rahulkmr1502/SentinelRecon

https://github.com/sanasimran1403-jpg/log4shell

https://github.com/vaishnavikkotian/log4shell-research

https://github.com/yili-soc/vm-homelab-log4shell-assessment

https://github.com/anubhavroshan1080-hub/argus

https://github.com/rezearcher/x402-cve-triage

https://github.com/Haojie-Corner/security-research-notes

https://github.com/JuttSahib1999/vuln-ai-assistant

https://github.com/MrEchoFi/docklab

https://github.com/SoftwareEngineeringInnovator/SBA-320H-React_Web_Application_Project

https://github.com/carlosalbertotuma/red.cve

https://github.com/ByteRay-AI/Xpsd

https://github.com/jcwoods/cve-skills

https://github.com/AdnaKoss/cve-rag-assistant

https://github.com/neeraj-sharma-0/cve-rag

https://github.com/Mollywc/cve-selective-risk

https://github.com/rahul0xkr/Cve-Management-API

https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction

https://github.com/avidzcheetah/CVE-Triage-Patch-agent

https://github.com/ftrout/sample-secops-copilot-agent

https://github.com/brian-mitchell-sec/http-bait

https://github.com/xiabai2008/poxiao

https://github.com/CVEasy/cveasy-mcp

https://github.com/jim-lahey69/snow-cve-risk-framework

https://github.com/Athology0000/cve-lab

https://github.com/stephent23/cve-analytics

https://github.com/devashridatta-dotcom/srap-toolkit

https://github.com/26zl/netsec-auditor

https://github.com/HaakimSec/zero2shell-50

https://github.com/arpitgupta369/log4shell-scanner

https://github.com/balajiltechai/order-service

https://github.com/SumitSonkusale/vulnerability-scanner-python

https://github.com/kidoz/vulners-py

https://github.com/Divolika/ioc-extractor

https://github.com/sudichai/cve-destroyer

https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026

https://github.com/prmawyer/log4shell-vulnerable-app

https://github.com/Harsh-Sonker/Security-News-Scraper

https://github.com/SlateGitOrg/vuln-priority-engine

https://github.com/rey11997/cvewatch

https://github.com/crimson-crawler/python-sdk

https://github.com/crimson-crawler/typescript-sdk

https://github.com/crimson-crawler/ccc

https://github.com/AstralJays/TraditionalJay

https://github.com/umaadi/truepositive-cli

https://github.com/BlastFog/cve-analyzer-notifier

https://github.com/mateusdias96cs/cve-triage-agent

https://github.com/notcve/mcp-server

https://github.com/JanetKesinro/CVE_Intelligence_Risk_Prioritization_Platform

https://github.com/marioolf/cve-plugin

https://github.com/kokunas/java-app-cve

https://github.com/datakoot/security-intel-mcp

https://github.com/zebbern/pocmap

https://github.com/Ninobt/Cybersecurity-Internship-Labs

https://github.com/michaelochoaa/cve-triage-agent

https://github.com/cybergirlApurva/security-automation-toolkit

https://github.com/CarterPerez-dev/nadezhda

https://github.com/noraj/euvd

https://github.com/haniszaim/Multi-Agent-Security-Triage-

https://github.com/pete-builds/mcp-nixreview

https://github.com/knumskull/cve-panorama

https://github.com/99-sketch/vuln-research-mcp

https://github.com/panda12332145/cve-vulnerability-scanner

https://github.com/iamnikitakhare/Cybersecurity-RAG

https://github.com/Cyber-protect/CVE-Assessor

https://github.com/shubhangamK/CVE-QA-BOT

https://github.com/blackhole8080-darkmatter/DEEP

https://github.com/BL3IP/iocsift

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/aakashsingh-sec/vulnerability-prioritization-dashboard

https://github.com/R4YANM/cve-triage

https://github.com/manahylkhan/cveradar

https://github.com/nMoncho/sbt-osv

https://github.com/lorenzozardo/cve-scope

https://github.com/armaanamin/cybersecurity-portfolio

https://github.com/test-avm-714877d2df585126/dependabot-cve-test-2

https://github.com/test-avm-714877d2df585126/dependabot-cve-test

https://github.com/RunTimeAdmin/sbomix

https://github.com/RunTimeAdmin/PACKRAI

https://github.com/phaasma/cveinsight

https://github.com/Query-farm/vgi-cve

https://github.com/akrishnash/secureai-agent

https://github.com/Lanexus/cve-scanner

https://github.com/hardikrathod777/Mend-Resolver-Agent

https://github.com/JakPot42/cve-prioritizer

https://github.com/cemheren/quicksheet-cve-ext

https://github.com/heyjerrybecker/seevie-pri

https://github.com/mehmetaksy/cybermcp

https://github.com/fDarkShadow/noctis

https://github.com/safetylab/ShadowSecurityScanner

https://github.com/rvzsec/ccc

https://github.com/DAADAISMYLIFE/log4shell-lab

https://github.com/harshweb-cyber/Netscout

https://github.com/cloudanimal/cve-remediation-agent

https://github.com/brainrotshiva/ThreatIntelAggregator

https://github.com/Sumeet-Y1/aws-devsecops-pipeline

https://github.com/sonnycroco/nuclei-index

https://github.com/limxuan/ehir-vuln-enterprise-login

https://github.com/Erik-Castro/DevSecurity

https://github.com/mstampfli/cve2detect

https://github.com/manojmallick/supplyguard

https://github.com/manueldotto01/cve-intel-agent

https://github.com/strawhat23/cve-intelligence-assistant

https://github.com/onefreeman1337/osf-langgraph-example

https://github.com/sumit760/cve-exploitability

https://github.com/rozetyp/vuln-intel-mcp

https://github.com/CamilaIsperling/CVEye

https://github.com/0DevDutt0/cybershield-ai-platform

https://github.com/Clocker34/CVE_Bot

https://github.com/pgmac-net/tremendous-cve

https://github.com/shreyash-dhawale/cve-advisory-publisher

https://github.com/Adam-KD/ioc-extractor

https://github.com/Finnete-20/sentinelai-soc-application

https://github.com/Revo445/cve-exposure-agent

https://github.com/RedSideSecurity/CVEAlertor

https://github.com/ashishghmr8848/CVE-Explained-For-Defenders

https://github.com/PERARASU10/cve-analyzer-pro

https://github.com/888irdy/vuln-analysis

https://github.com/888irdy/cve-research

https://github.com/hmxh123/Log4Shell-Vulnerability-Replication

https://github.com/vishal755/cve-remediation-project

https://github.com/Jagadish-builds/CveNet

https://github.com/cognis-digital/sbomb

https://github.com/cognis-digital/shipcheck

https://github.com/omobolajiadeyan/vulngpt

https://github.com/Sansyuh06/CVE-Guard

https://github.com/HypedHavoc/nvd-cve-vulnerability-database

https://github.com/kvsaurav/CVE-prioritization-

https://github.com/Karma4488/kArmas_CVEscan

https://github.com/bhimsekhar/vulnfix-agent

https://github.com/bhimsekhar/vulnerable-java-app

https://github.com/mrjoker-web/CVE-Research-Tool-v3.0

https://github.com/h4ckl07d/CVELens

https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE

https://github.com/TR-Space/CVE-Learning-Agent

Details

Source: Mitre, NVD

Published: 2021-12-10

Updated: 2026-08-11

Named Vulnerability: Log4jNamed Vulnerability: Log4ShellNamed Vulnerability: Log4JKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99999