Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33382
HistoryDec 18, 2021 - 6:53 p.m.

Denial Of Service (DoS)

2021-12-1818:53:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.966 High

EPSS

Percentile

99.6%

log4j is vulnerable to denial of service. An attacker with control over Thread Context Map (MDC) input data is able to cause a denial of service by causing a StackOverflowError that will terminate the process. This is due to uncontrolled recursion from self-referential lookups when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}).

References