Lucene search

K
osvGoogleOSV:USN-5203-1
HistoryDec 19, 2021 - 5:39 p.m.

apache-log4j2 vulnerability

2021-12-1917:39:38
Google
osv.dev
8

6.4 Medium

AI Score

Confidence

High

0.966 High

EPSS

Percentile

99.6%

Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not
protect against infinite recursion in lookup evaluation. A remote attacker
could possibly use this issue to cause Apache Log4j 2 to crash, leading to
a denial of service.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell