Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33476
HistoryDec 29, 2021 - 1:02 a.m.

Remote Code Execution (RCE)

2021-12-2901:02:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
219

0.022 Low

EPSS

Percentile

89.6%

log4j-core is vulnerable to remote code execution. Lack of limiting JNDI access to data source names allows an attacker with privilege to modify logging configuration to send malicious configuration via JDBC Appender with a data source referencing a JNDI URI.

References