Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
https://security.netapp.com/advisory/ntap-20220104-0001/
https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html
https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf
https://www.tenable.com/blog/oracle-january-2023-critical-patch-update-addresses-183-cves
https://www.tenable.com/blog/oracle-april-2022-critical-patch-update-addresses-221-cves
https://www.tenable.com/blog/oracle-january-2022-critical-patch-update-addresses-266-cves
https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction
https://github.com/heyjerrybecker/seevie-pri
https://github.com/Sumeet-Y1/aws-devsecops-pipeline
https://github.com/rozetyp/vuln-intel-mcp
https://github.com/cognis-digital/sbomb
https://github.com/urunsiyabend/depintel
https://github.com/B1ack4sh/Blackash-CVE-2021-44228
https://github.com/arabindadora/log4shell
https://github.com/zgimszhd61/CVE-PoC-ThreatHub
https://github.com/demonrvm/Log4ShellRemediation
https://github.com/advisories/GHSA-v57x-gxfj-484q
https://github.com/advisories/GHSA-8489-44mv-ggj8
https://github.com/DanielRuf/CVE-2021-44832
https://github.com/charliemaddex/log4j
https://github.com/andalik/log4j-filescan
https://github.com/HynekPetrak/log4shell-finder
https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143