It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Published: 2021-12-17
A list of frequently asked questions related to Log4Shell and associated vulnerabilities.
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/alert-cve-2021-44228.html
https://www.kb.cert.org/vuls/id/930724
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html
https://www.debian.org/security/2021/dsa-5022
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
https://security.gentoo.org/glsa/202310-16
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032
https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf
http://www.openwall.com/lists/oss-security/2021/12/18/1
https://blog.talosintelligence.com/year-in-review-vulnerabilities-old-and-new-and-something-react2/
https://thehackernews.com/2023/12/behind-scenes-of-matveevs-ransomware.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/blog/frequently-asked-questions-about-iranian-cyber-operations
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://www.tenable.com/blog/oracle-january-2022-critical-patch-update-addresses-266-cves
https://github.com/BogdanStamenovic/vsearch
https://github.com/saaheerpurav/cve-twin
https://github.com/Induj1/cve-twin
https://github.com/chengbochuan3/CVE-Apache-Ecosystem
https://github.com/RaajitSingh1306/ThreatMind
https://github.com/DeathReaper00/CVE-Project
https://github.com/jcwoods/cve-skills
https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction
https://github.com/arpitgupta369/log4shell-scanner
https://github.com/kokunas/java-app-cve
https://github.com/zebbern/pocmap
https://github.com/Sumeet-Y1/aws-devsecops-pipeline
https://github.com/cognis-digital/sbomb
https://github.com/cognis-digital/shipcheck
https://github.com/neilc1964techned/craready-test-java-vulns
https://github.com/yashmoar11/RAG-poison
https://github.com/kaleth4/CVE-2021-44228
https://github.com/urunsiyabend/depintel
https://github.com/palvevaibhav/cvecheck
https://github.com/tunakum/spektr
https://github.com/marvang/vuln-variants
https://github.com/hermestoola/bb-hunter-pro
https://github.com/apifyforge/open-source-supply-chain-risk-mcp
https://github.com/rebugui/open-cve-scanner
https://github.com/venubhamidi/concert-cve-demo
https://github.com/kidoz/go-vulners
https://github.com/yksanjo/vuln-mcp-server
https://github.com/liuayng201314/CveTracer
https://github.com/ddamme05/slack-mcp-cve
https://github.com/B1ack4sh/Blackash-CVE-2021-44228
https://github.com/arabindadora/log4shell
https://github.com/ozGod-sh/Declencheur-CVE
https://github.com/ifconfig-me/Log4Shell-Payloads
https://github.com/fabioeletto/hka-seminar-log4shell
https://github.com/Elijah3756/vulnerabililizer
https://github.com/Chrisync/CVE-Scanner
https://github.com/abozzoni/cve-app
https://github.com/binkley/modern-java-practices
https://github.com/demonrvm/Log4ShellRemediation
https://github.com/demining/Log4j-Vulnerability
https://github.com/Live-Hack-CVE/CVE-2021-4125
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
https://github.com/advisories/GHSA-v57x-gxfj-484q
https://github.com/taise-hub/log4j-poc
https://github.com/CaptanMoss/Log4Shell-Sandbox-Signature
https://github.com/lijiejie/log4j2_vul_local_scanner
https://github.com/sudo6/l4shunter
https://github.com/TheInterception/Log4J-Simulation-Tool
https://github.com/trickyearlobe/inspec-log4j
https://github.com/TheInterception/Log4JPentester
https://github.com/DANSI/PowerShell-Log4J-Scanner
https://github.com/lukepasek/log4jjndilookupremove
https://github.com/Aschen/log4j-patched
https://github.com/mergebase/log4j-samples
https://github.com/andalik/log4j-filescan
https://github.com/DXC-StrikeForce/Burp-Log4j-HammerTime
https://github.com/yahoo/check-log4j
https://github.com/tejas-nagchandi/CVE-2021-45046
https://github.com/gitlab-de/log4j-resources
https://github.com/cckuailong/Log4j_CVE-2021-45046
https://github.com/HynekPetrak/log4shell_finder
https://github.com/HynekPetrak/log4shell-finder
https://github.com/advisories/GHSA-7rjr-3q55-vv33
https://github.com/fox-it/log4j-finder
https://github.com/benarculus/detecting-cve-2021-44228
https://github.com/alexbakker/log4shell-tools
https://github.com/X1pe0/Log4J-Scan-Win
https://github.com/0xsyr0/Log4Shell
https://github.com/fullhunt/log4j-scan
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/mergebase/log4j-detector
https://github.com/advisories/GHSA-jfh8-c2jp-5v3q
https://www.cve.org/CVERecord?id=CVE-2021-44228
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046
Published: 2021-12-14
Updated: 2026-06-17
Named Vulnerability: Log4ShellKnown Exploited Vulnerability (KEV)
Base Score: 5.1
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 9
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99977