← Back to browse · API

CVE-2021-45105

Severity
MEDIUM
CVSS
5.9
EPSS
0.99999
Risk score
58.6
CISA KEV
No
PoC
No
Published
2021-12-18
Modified
2026-05-29
First seen
2026-08-07
Aliases
EUVD-2021-2559, GHSA-P6XC-XR62-6R2G
Products
Apache Software Foundation:Apache Log4j2 log4j-core <2.17.0
Sources
euvd EUVD-2021-2559

Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

References