Lucene search

K
cisaCISACISA:6C962B804E593B231FDE50912F4D093A
HistoryDec 10, 2021 - 12:00 a.m.

Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation

2021-12-1000:00:00
us-cert.cisa.gov
167
apache
log4j
rce vulnerability
security advisory
cve-2021-44228
java logging utility
cisa
upgrade
mitigations
privacy policy
product survey

EPSS

0.965

Percentile

99.6%

The Apache Software Foundation has released a security advisory to address a remote code execution vulnerability (CVE-2021-44228) affecting Log4j versions 2.0-beta9 to 2.14.1. A remote attacker could exploit this vulnerability to take control of an affected system. Log4j is an open-source, Java-based logging utility widely used by enterprise applications and cloud services.

CISA encourages users and administrators to review the Apache Log4j 2.15.0 Announcement and upgrade to Log4j 2.15.0 or apply the recommended mitigations immediately.

This product is provided subject to this Notification and this Privacy & Use policy.

Please share your thoughts.

We recently updated our anonymous product survey; we’d welcome your feedback.