CVE-2021-45046

critical

Description

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

From the Tenable Blog

CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities

Published: 2021-12-17

A list of frequently asked questions related to Log4Shell and associated vulnerabilities.

References

https://github.com/BogdanStamenovic/vsearch

https://github.com/saaheerpurav/cve-twin

https://github.com/Induj1/cve-twin

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/RaajitSingh1306/ThreatMind

https://github.com/DeathReaper00/CVE-Project

https://github.com/jcwoods/cve-skills

https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction

https://github.com/arpitgupta369/log4shell-scanner

https://github.com/kokunas/java-app-cve

https://github.com/zebbern/pocmap

https://github.com/noraj/euvd

https://github.com/Sumeet-Y1/aws-devsecops-pipeline

https://github.com/cognis-digital/sbomb

https://github.com/cognis-digital/shipcheck

https://github.com/neilc1964techned/craready-test-java-vulns

https://github.com/yashmoar11/RAG-poison

https://github.com/kaleth4/CVE-2021-44228

https://github.com/urunsiyabend/depintel

https://github.com/palvevaibhav/cvecheck

https://github.com/tunakum/spektr

https://github.com/marvang/vuln-variants

https://github.com/hermestoola/bb-hunter-pro

https://github.com/apifyforge/open-source-supply-chain-risk-mcp

https://github.com/rebugui/open-cve-scanner

https://github.com/venubhamidi/concert-cve-demo

https://github.com/kidoz/go-vulners

https://github.com/yksanjo/vuln-mcp-server

https://github.com/liuayng201314/CveTracer

https://github.com/ddamme05/slack-mcp-cve

https://github.com/B1ack4sh/Blackash-CVE-2021-44228

https://github.com/arabindadora/log4shell

https://github.com/ozGod-sh/Declencheur-CVE

https://github.com/ifconfig-me/Log4Shell-Payloads

https://github.com/fabioeletto/hka-seminar-log4shell

https://github.com/Elijah3756/vulnerabililizer

https://github.com/Chrisync/CVE-Scanner

https://github.com/abozzoni/cve-app

https://github.com/binkley/modern-java-practices

https://github.com/demonrvm/Log4ShellRemediation

https://github.com/demining/Log4j-Vulnerability

https://github.com/Live-Hack-CVE/CVE-2021-4125

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

https://github.com/advisories/GHSA-v57x-gxfj-484q

https://github.com/taise-hub/log4j-poc

https://github.com/CaptanMoss/Log4Shell-Sandbox-Signature

https://github.com/lijiejie/log4j2_vul_local_scanner

https://github.com/sudo6/l4shunter

https://github.com/TheInterception/Log4J-Simulation-Tool

https://github.com/trickyearlobe/inspec-log4j

https://github.com/TheInterception/Log4JPentester

https://github.com/DANSI/PowerShell-Log4J-Scanner

https://github.com/lukepasek/log4jjndilookupremove

https://github.com/Aschen/log4j-patched

https://github.com/mergebase/log4j-samples

https://github.com/andalik/log4j-filescan

https://github.com/DXC-StrikeForce/Burp-Log4j-HammerTime

https://github.com/yahoo/check-log4j

https://github.com/tejas-nagchandi/CVE-2021-45046

https://github.com/gitlab-de/log4j-resources

https://github.com/cckuailong/Log4j_CVE-2021-45046

https://github.com/HynekPetrak/log4shell_finder

https://github.com/HynekPetrak/log4shell-finder

https://github.com/advisories/GHSA-7rjr-3q55-vv33

https://github.com/fox-it/log4j-finder

https://github.com/benarculus/detecting-cve-2021-44228

https://github.com/alexbakker/log4shell-tools

https://github.com/X1pe0/Log4J-Scan-Win

https://github.com/0xsyr0/Log4Shell

https://github.com/fullhunt/log4j-scan

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/mergebase/log4j-detector

https://github.com/advisories/GHSA-jfh8-c2jp-5v3q

https://www.cve.org/CVERecord?id=CVE-2021-44228

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046

https://logging.apache.org/log4j/2.x/security.html

Details

Source: Mitre, NVD

Published: 2021-12-14

Updated: 2026-06-17

Named Vulnerability: Log4ShellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 5.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99977