CVE Feed

    Dashboard / CVE / CVE-2021-44228

    CVE-2021-44228

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

    Published:Dec 10, 2021
    Last Modified:Aug 11, 2026
    EPS:Dec 10, 2021
    EPSS Score:0.99999
    CVSS Score:10

    CISA Notification

    Description

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

    Required Action:

    For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

    Notes:

    No extra notes provided.

    Due Date
    Dec 24, 2021
    1722 days ago
    Alert Date
    Dec 10, 2021
    1736 days ago

    Affected Products

    Vendor
    Apache
    Product
    Log4j
    Vendor
    Apple
    Product
    Xcode
    Vendor
    Bentley
    Product
    Synchro
    Vendor
    Bentley
    Product
    Synchro 4d
    Vendor
    Cisco
    Product
    Advanced Malware Protection Virtual Private Cloud Appliance
    Vendor
    Cisco
    Product
    Automated Subsea Tuning
    Vendor
    Cisco
    Product
    Broadworks
    Vendor
    Cisco
    Product
    Business Process Automation
    Vendor
    Cisco
    Product
    Cloud Connect
    Vendor
    Cisco
    Product
    Cloudcenter
    Vendor
    Cisco
    Product
    Cloudcenter Cost Optimizer
    Vendor
    Cisco
    Product
    Cloudcenter Suite
    Vendor
    Cisco
    Product
    Cloudcenter Suite Admin
    Vendor
    Cisco
    Product
    Cloudcenter Workload Manager
    Vendor
    Cisco
    Product
    Common Services Platform Collector
    Vendor
    Cisco
    Product
    Connected Mobile Experiences
    Vendor
    Cisco
    Product
    Contact Center Domain Manager
    Vendor
    Cisco
    Product
    Contact Center Management Portal
    Vendor
    Cisco
    Product
    Crosswork Data Gateway
    Vendor
    Cisco
    Product
    Crosswork Network Automation
    Vendor
    Cisco
    Product
    Crosswork Network Controller
    Vendor
    Cisco
    Product
    Crosswork Optimization Engine
    Vendor
    Cisco
    Product
    Crosswork Platform Infrastructure
    Vendor
    Cisco
    Product
    Crosswork Zero Touch Provisioning
    Vendor
    Cisco
    Product
    Customer Experience Cloud Agent
    Vendor
    Cisco
    Product
    Cx Cloud Agent
    Vendor
    Cisco
    Product
    Cyber Vision
    Vendor
    Cisco
    Product
    Cyber Vision Sensor Management Extension
    Vendor
    Cisco
    Product
    Data Center Network Manager
    Vendor
    Cisco
    Product
    Dna Center
    Vendor
    Cisco
    Product
    Dna Spaces
    Vendor
    Cisco
    Product
    Dna Spaces\
    Vendor
    Cisco
    Product
    Dna Spaces Connector
    Vendor
    Cisco
    Product
    Emergency Responder
    Vendor
    Cisco
    Product
    Enterprise Chat And Email
    Vendor
    Cisco
    Product
    Evolved Programmable Network Manager
    Vendor
    Cisco
    Product
    Finesse
    Vendor
    Cisco
    Product
    Firepower 1010
    Vendor
    Cisco
    Product
    Firepower 1120
    Vendor
    Cisco
    Product
    Firepower 1140
    Vendor
    Cisco
    Product
    Firepower 1150
    Vendor
    Cisco
    Product
    Firepower 2110
    Vendor
    Cisco
    Product
    Firepower 2120
    Vendor
    Cisco
    Product
    Firepower 2130
    Vendor
    Cisco
    Product
    Firepower 2140
    Vendor
    Cisco
    Product
    Firepower 4110
    Vendor
    Cisco
    Product
    Firepower 4112
    Vendor
    Cisco
    Product
    Firepower 4115
    Vendor
    Cisco
    Product
    Firepower 4120
    Vendor
    Cisco
    Product
    Firepower 4125
    Vendor
    Cisco
    Product
    Firepower 4140
    Vendor
    Cisco
    Product
    Firepower 4145
    Vendor
    Cisco
    Product
    Firepower 4150
    Vendor
    Cisco
    Product
    Firepower 9300
    Vendor
    Cisco
    Product
    Fog Director
    Vendor
    Cisco
    Product
    Fxos
    Vendor
    Cisco
    Product
    Identity Services Engine
    Vendor
    Cisco
    Product
    Integrated Management Controller Supervisor
    Vendor
    Cisco
    Product
    Intersight Virtual Appliance
    Vendor
    Cisco
    Product
    Iot Operations Dashboard
    Vendor
    Cisco
    Product
    Mobility Services Engine
    Vendor
    Cisco
    Product
    Network Assurance Engine
    Vendor
    Cisco
    Product
    Network Dashboard Fabric Controller
    Vendor
    Cisco
    Product
    Network Insights For Data Center
    Vendor
    Cisco
    Product
    Network Services Orchestrator
    Vendor
    Cisco
    Product
    Nexus Dashboard
    Vendor
    Cisco
    Product
    Nexus Insights
    Vendor
    Cisco
    Product
    Optical Network Controller
    Vendor
    Cisco
    Product
    Packaged Contact Center Enterprise
    Vendor
    Cisco
    Product
    Paging Server
    Vendor
    Cisco
    Product
    Prime Service Catalog
    Vendor
    Cisco
    Product
    Sd-wan Vmanage
    Vendor
    Cisco
    Product
    Secure Firewall Threat Defense
    Vendor
    Cisco
    Product
    Smart Phy
    Vendor
    Cisco
    Product
    Ucs Central
    Vendor
    Cisco
    Product
    Ucs Central Software
    Vendor
    Cisco
    Product
    Ucs Director
    Vendor
    Cisco
    Product
    Unified Communications Manager
    Vendor
    Cisco
    Product
    Unified Communications Manager Im \& Presence Service
    Vendor
    Cisco
    Product
    Unified Communications Manager Im And Presence Service
    Vendor
    Cisco
    Product
    Unified Computing System
    Vendor
    Cisco
    Product
    Unified Contact Center Enterprise
    Vendor
    Cisco
    Product
    Unified Contact Center Express
    Vendor
    Cisco
    Product
    Unified Contact Center Management Portal
    Vendor
    Cisco
    Product
    Unified Customer Voice Portal
    Vendor
    Cisco
    Product
    Unified Intelligence Center
    Vendor
    Cisco
    Product
    Unified Sip Proxy
    Vendor
    Cisco
    Product
    Unified Workforce Optimization
    Vendor
    Cisco
    Product
    Unity Connection
    Vendor
    Cisco
    Product
    Video Surveillance Manager
    Vendor
    Cisco
    Product
    Video Surveillance Operations Manager
    Vendor
    Cisco
    Product
    Virtual Topology System
    Vendor
    Cisco
    Product
    Virtualized Infrastructure Manager
    Vendor
    Cisco
    Product
    Virtualized Voice Browser
    Vendor
    Cisco
    Product
    Wan Automation Engine
    Vendor
    Cisco
    Product
    Webex Meetings Server
    Vendor
    Cisco
    Product
    Workload Optimization Manager
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Intel
    Product
    Computer Vision Annotation Tool
    Vendor
    Intel
    Product
    Datacenter Manager
    Vendor
    Intel
    Product
    Genomics Kernel Library
    Vendor
    Intel
    Product
    Oneapi Sample Browser
    Vendor
    Intel
    Product
    Secure Device Onboard
    Vendor
    Intel
    Product
    System Studio
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Brocade San Navigator
    Vendor
    Netapp
    Product
    Cloud Insights
    Vendor
    Netapp
    Product
    Cloud Manager
    Vendor
    Netapp
    Product
    Cloud Secure Agent
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Ontap Tools
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Netapp
    Product
    Solidfire \& Hci Storage Node
    Vendor
    Netapp
    Product
    Solidfire Enterprise Sds
    Vendor
    Percussion
    Product
    Rhythmyx
    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Integration
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform Eus
    Vendor
    Redhat
    Product
    Jboss Enterprise Bpms Platform
    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Redhat
    Product
    Logging
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Openshift Application Runtimes
    Vendor
    Siemens
    Product
    6bk1602-0aa12-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa12-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa22-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa22-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa32-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa32-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa42-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa42-0tp0 Firmware
    Vendor
    Siemens
    Product
    6bk1602-0aa52-0tp0
    Vendor
    Siemens
    Product
    6bk1602-0aa52-0tp0 Firmware
    Vendor
    Siemens
    Product
    Capital
    Vendor
    Siemens
    Product
    Comos
    Vendor
    Siemens
    Product
    Desigo Cc Advanced Reports
    Vendor
    Siemens
    Product
    Desigo Cc Info Center
    Vendor
    Siemens
    Product
    E-car Operation Center
    Vendor
    Siemens
    Product
    Energy Engage
    Vendor
    Siemens
    Product
    Energyip
    Vendor
    Siemens
    Product
    Energyip Prepay
    Vendor
    Siemens
    Product
    Gma-manager
    Vendor
    Siemens
    Product
    Head-end System Universal Device Integration System
    Vendor
    Siemens
    Product
    Industrial Edge Management
    Vendor
    Siemens
    Product
    Industrial Edge Management Hub
    Vendor
    Siemens
    Product
    Logo\! Soft Comfort
    Vendor
    Siemens
    Product
    Mendix
    Vendor
    Siemens
    Product
    Mindsphere
    Vendor
    Siemens
    Product
    Navigator
    Vendor
    Siemens
    Product
    Nx
    Vendor
    Siemens
    Product
    Opcenter Intelligence
    Vendor
    Siemens
    Product
    Operation Scheduler
    Vendor
    Siemens
    Product
    Sentron Powermanager
    Vendor
    Siemens
    Product
    Siguard Dsa
    Vendor
    Siemens
    Product
    Sipass Integrated
    Vendor
    Siemens
    Product
    Siveillance Command
    Vendor
    Siemens
    Product
    Siveillance Control Pro
    Vendor
    Siemens
    Product
    Siveillance Identity
    Vendor
    Siemens
    Product
    Siveillance Vantage
    Vendor
    Siemens
    Product
    Siveillance Viewpoint
    Vendor
    Siemens
    Product
    Solid Edge Cam Pro
    Vendor
    Siemens
    Product
    Solid Edge Harness Design
    Vendor
    Siemens
    Product
    Spectrum Power 4
    Vendor
    Siemens
    Product
    Spectrum Power 7
    Vendor
    Siemens
    Product
    Sppa-t3000 Ses3000
    Vendor
    Siemens
    Product
    Sppa-t3000 Ses3000 Firmware
    Vendor
    Siemens
    Product
    Teamcenter
    Vendor
    Siemens
    Product
    Vesys
    Vendor
    Siemens
    Product
    Xpedition Enterprise
    Vendor
    Siemens
    Product
    Xpedition Package Integrator
    Vendor
    Snowsoftware
    Product
    Snow Commander
    Vendor
    Snowsoftware
    Product
    Vm Access Proxy
    Vendor
    Sonicwall
    Product
    Email Security

    Exploits

    http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlhttp://seclists.org/fulldisclosure/2022/Dec/2https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228https://twitter.com/kurtseifried/status/1469345530182455296https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlhttp://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlhttp://seclists.org/fulldisclosure/2022/Dec/2https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228https://twitter.com/kurtseifried/status/1469345530182455296https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlhttps://www.exploit-db.com/exploits/51183https://github.com/0xalwayslucky/log4j-polkit-pochttps://github.com/0xAshwesker/CVE-2021-44228https://github.com/0xBlackash/CVE-2021-44228https://github.com/0xDexter0us/Log4J-Scannerhttps://github.com/0xInfection/LogMePwnhttps://github.com/0xRyan/log4j-nullroutehttps://github.com/0xsyr0/Log4Shellhttps://github.com/0xThiebaut/CVE-2021-44228https://github.com/14free/log4j2-vuln-labhttps://github.com/1hakusai1/log4j-rce-CVE-2021-44228https://github.com/1in9e/Apache-Log4j2-RCEhttps://github.com/1lann/log4shelldetecthttps://github.com/34zY/JNDI-Exploit-1.2-log4shellhttps://github.com/3pplus/loguccinohttps://github.com/4jfinder/4jfinder.github.iohttps://github.com/53buahapel/log4shell-vulnwebhttps://github.com/aajuvonen/log4stdinhttps://github.com/aaronm-sysdig/log4j-vuln-demohttps://github.com/ab0x90/CVE-2021-44228_PoChttps://github.com/Adikso/minecraft-log4j-honeypothttps://github.com/agylabs/log4shell-remediationhttps://github.com/AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-https://github.com/AhndreWalters/ProjectSecurity-Homelabhttps://github.com/Alan-coder-eng/log4j-cve-2021-44228-https://github.com/alenazi90/log4jhttps://github.com/AlexandreHeroux/Fix-CVE-2021-44228https://github.com/alexandre-lavoie/python-log4rcehttps://github.com/alexandreroman/cve-2021-44228-workaround-buildpackhttps://github.com/alexbakker/log4shell-toolshttps://github.com/alexpena5635/CVE-2021-44228_scanner-main-Modified-https://github.com/alpacamybags118/log4j-cve-2021-44228-samplehttps://github.com/Ananya-0306/Log-4j-scannerhttps://github.com/andalik/log4j-filescanhttps://github.com/andrii-kovalenko-celonis/log4j-vulnerability-demohttps://github.com/andypitcher/Log4J_checkerhttps://github.com/ankur-katiyar/log4j-dockerhttps://github.com/anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228https://github.com/Apipia/log4j-pcap-activityhttps://github.com/arabindadora/log4shellhttps://github.com/arnaudluti/PS-CVE-2021-44228https://github.com/arpitgupta369/log4shell-scannerhttps://github.com/Aschen/log4j-patchedhttps://github.com/asd58584388/CVE-2021-44228https://github.com/Ashwesker/Blackash-CVE-2021-44228https://github.com/AstralJays/TraditionalJayhttps://github.com/atlassion/log4j-exploit-builderhttps://github.com/atlassion/RS4LOGJ-CVE-2021-44228https://github.com/atnetws/fail2ban-log4jhttps://github.com/authomize/log4j-log4shell-affectedhttps://github.com/avirahul007/CVE-2021-44228https://github.com/avwolferen/Sitecore.Solr-log4j-mitigationhttps://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agenthttps://github.com/axelcurmi/log4shell-docker-labhttps://github.com/axisops/CVE-2021-44228https://github.com/Azeemering/CVE-2021-44228-DFIR-Noteshttps://github.com/B1ack4sh/Blackash-CVE-2021-44228https://github.com/b1tm0n3r/CVE-2021-44228https://github.com/b-abderrahmane/CVE-2021-44228-playgroundhttps://github.com/BabooPan/Log4Shell-CVE-2021-44228-Demohttps://github.com/back2root/log4shell-rexhttps://github.com/badb33f/Apache-Log4j-POChttps://github.com/bcdunbar/CVE-2021-44228-pochttps://github.com/ben-smash/l4j-infohttps://github.com/bhimsekhar/vulnerable-java-apphttps://github.com/bhprin/log4j-vulhttps://github.com/bigsizeme/Log4j-checkhttps://github.com/BinaryDefense/log4j-honeypot-flaskhttps://github.com/binganao/Log4j2-RCEhttps://github.com/BJLIYANLIANG/log4j-scannerhttps://github.com/blake-fm/vcenter-log4jhttps://github.com/boundaryx/cloudrasp-log4j2https://github.com/bsigouin/log4shell-vulnerable-apphttps://github.com/bumheehan/cve-2021-44228-log4j-testhttps://github.com/byteboycn/CVE-2021-44228-Apache-Log4j-Rcehttps://github.com/C00LN3T/Log4ShellAuditorhttps://github.com/c3-h2/Log4j_Attacker_IPListhttps://github.com/cado-security/log4shellhttps://github.com/Camphul/log4shell-spring-framework-researchhttps://github.com/Carlos-Mesquita/TPASLog4ShellPoChttps://github.com/cbuschka/log4j2-rce-recaphttps://github.com/CERTCC/CVE-2021-44228_scannerhttps://github.com/ChandanShastri/Log4j_Vulnerability_Demohttps://github.com/chandru-gunasekaran/log4j-fix-CVE-2021-44228https://github.com/chilit-nl/log4shell-examplehttps://github.com/chilliwebs/CVE-2021-44228_Examplehttps://github.com/christophetd/log4shell-vulnerable-apphttps://github.com/claranet/ansible-role-log4shellhttps://github.com/Codepumpking/log4shell-pochttps://github.com/CodeShield-Security/Log4JShell-Bytecode-Detectorhttps://github.com/codiobert/log4j-scannerhttps://github.com/ColdFusionX/CVE-2021-44228-Log4Shell-POChttps://github.com/Contrast-Security-OSS/CVE-2021-44228https://github.com/corelight/cve-2021-44228https://github.com/corneacristian/Log4J-CVE-2021-44228-RCEhttps://github.com/corretto/hotpatch-for-apache-log4j2https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloadshttps://github.com/Crane-Mocker/log4j-pochttps://github.com/creamIcec/CVE-2021-44228-Apache-Log4j-Rce__reviewhttps://github.com/CreeperHost/Log4jPatcherhttps://github.com/cuijiung/log4j-CVE-2021-44228https://github.com/cybersecurityworks553/log4j-shell-cswhttps://github.com/cyberxml/log4j-pochttps://github.com/d4ngkh04w/CVE-2021-44228-Apache-Log4j2https://github.com/DAADAISMYLIFE/log4shell-labhttps://github.com/danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-https://github.com/DANSI/PowerShell-Log4J-Scannerhttps://github.com/darkarnium/Log4j-CVE-Detecthttps://github.com/dark-ninja10/Log4j-CVE-2021-44228https://github.com/datadavev/test-44228https://github.com/dbgee/CVE-2021-44228https://github.com/dbwlsdnr95/CVE-2021-44228https://github.com/dbwlsdnr95/CVE-2021-44228-log4shellhttps://github.com/dbzoo/log4j_scannerhttps://github.com/dcm2406/CVE-Labhttps://github.com/demining/Log4j-Vulnerabilityhttps://github.com/demonrvm/Log4ShellRemediationhttps://github.com/DiCanio/CVE-2021-44228-docker-examplehttps://github.com/didoatanasov/cve-2021-44228https://github.com/digital-dev/Log4j-CVE-2021-44228-Remediationhttps://github.com/Diverto/nse-log4shellhttps://github.com/dmitsuo/log4shell-war-fixerhttps://github.com/dotPY-hax/log4pyhttps://github.com/dpomnean/log4j_scanner_wrapperhttps://github.com/DragonSurvivalEU/RCEhttps://github.com/DrHaitham/Log4Shell-CVE-2021-44228https://github.com/dtact/divd-2021-00038--log4j-scannerhttps://github.com/DXC-StrikeForce/Burp-Log4j-HammerTimehttps://github.com/eurogig/jankybankhttps://github.com/f0ng/log4j2burpscannerhttps://github.com/fabioeletto/hka-seminar-log4shellhttps://github.com/FacundoMfernandez/pentesting-obiobahttps://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshellhttps://github.com/Fauzan-Aldi/Log4j-_Vulnerabilityhttps://github.com/Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228https://github.com/felipe8398/ModSec-log4j2https://github.com/felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-https://github.com/felixslama/log4shell-minecraft-demohttps://github.com/FeryaelJustice/Log4Shellhttps://github.com/fireeye/CVE-2021-44228https://github.com/fireflyingup/log4j-pochttps://github.com/flxhaas/Scan-CVE-2021-44228https://github.com/fox-it/log4j-finderhttps://github.com/fullhunt/log4j-scanhttps://github.com/funcid/log4j-exploit-fork-bombhttps://github.com/future-client/CVE-2021-44228https://github.com/gauthamg/log4j2021_vul_testhttps://github.com/gcmurphy/chk_log4jhttps://github.com/george-petrakis/log4j-scanner-CVE-2021-44228https://github.com/giterlizzi/nmap-log4shellhttps://github.com/gitlab-de/log4j-resourceshttps://github.com/Glease/Healerhttps://github.com/greymd/CVE-2021-44228https://github.com/grimch/log4j-CVE-2021-44228-workaroundhttps://github.com/Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCEhttps://github.com/guardicode/CVE-2021-44228_IoCshttps://github.com/guerzon/log4shellpochttps://github.com/gyaansastra/CVE-2021-44228https://github.com/Gyrfalc0n/scanlist-log4jhttps://github.com/hackinghippo/log4shell_ioc_ipshttps://github.com/halibobor/log4j2https://github.com/hassaanahmad813/log4jhttps://github.com/helsecert/CVE-2021-44228https://github.com/hmxh123/Log4Shell-Vulnerability-Replicationhttps://github.com/Hoanle396/CVE-2021-44228-demohttps://github.com/honeynet/log4shell-datahttps://github.com/honypot/CVE-2021-44228https://github.com/honypot/CVE-2021-44228-vuln-apphttps://github.com/horrister/log4shell-cve-2021-44228https://github.com/hotpotcookie/CVE-2021-44228-white-boxhttps://github.com/hozyx/log4shellhttps://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concepthttps://github.com/Hydragyrum/evil-rmi-serverhttps://github.com/HynekPetrak/log4shell-finderhttps://github.com/IAmNewbieZ/CVE-2021-44228https://github.com/immunityinc/Log4j-JNDIServerhttps://github.com/inettgmbh/checkmk-log4j-scannerhttps://github.com/infiniroot/nginx-mitigate-log4shellhttps://github.com/intel-xeon/CVE-2021-44228---detection-with-PowerShellhttps://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228https://github.com/isuruwa/Log4jhttps://github.com/izzyacademy/log4shell-mitigationhttps://github.com/j3kz/CVE-2021-44228-PoChttps://github.com/jacobtread/L4J-Vuln-Patchhttps://github.com/jaehnri/CVE-2021-44228https://github.com/jas502n/Log4j2-CVE-2021-44228https://github.com/jdormannn/SecureOps-Labhttps://github.com/jeffbryner/log4j-docker-vaccinehttps://github.com/jeffli1024/log4j-rce-testhttps://github.com/jeremyrsellars/CVE-2021-44228_scannerhttps://github.com/Jeromeyoung/log4j2burpscannerhttps://github.com/Jiahong-Guan/log4j-shell-pochttps://github.com/JiuBanSec/Log4j-CVE-2021-44228https://github.com/joaovicdev/EXPLOIT-CVE-2021-44228https://github.com/Joefreedy/Log4j-Windows-Scannerhttps://github.com/jomjosh17/Log4Shell-CVE-2021-44228-https://github.com/JoseMariaMicoli/Log4Shell-PoChttps://github.com/jrocia/Search-log4Jvuln-AppScanSTDhttps://github.com/julian911015/Log4j-Scanner-Exploithttps://github.com/Jun-5heng/CVE-2021-44228https://github.com/justakazh/Log4j-CVE-2021-44228https://github.com/JustinDPerkins/C1-WS-LOG4SHELLhttps://github.com/jxerome/log4shellhttps://github.com/jyotisahu98/logpresso-CVE-2021-44228-Scannerhttps://github.com/Kadantte/CVE-2021-44228-pochttps://github.com/kal1gh0st/MyLog4Shellhttps://github.com/kaleth4/CVE-2021-44228https://github.com/kali-dass/CVE-2021-44228-log4Shellhttps://github.com/KalidouLabghaly/log4shell-exploitation-detectionhttps://github.com/KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-devicehttps://github.com/kanitan/log4j2-web-vulnerablehttps://github.com/kannthu/CVE-2021-44228-Apache-Log4j-Rcehttps://github.com/kek-Sec/log4j-scanner-CVE-2021-44228https://github.com/KeysAU/Get-log4j-Windows-localhttps://github.com/KeysAU/Get-log4j-Windows.ps1https://github.com/khaidtraivch/CVE-2021-44228-Log4Shell-https://github.com/kimobu/cve-2021-44228https://github.com/KirkDJohnson/Wiresharkhttps://github.com/kkyehit/log4j_CVE-2021-44228https://github.com/korteke/log4shell-demohttps://github.com/KosmX/CVE-2021-44228-examplehttps://github.com/kossatzd/log4j-CVE-2021-44228-testhttps://github.com/Koupah/MC-Log4j-Patcherhttps://github.com/kozmer/log4j-shell-pochttps://github.com/Kr0ff/CVE-2021-44228https://github.com/KtokKawu/l4s-vulnapphttps://github.com/kubearmor/log4j-CVE-2021-44228https://github.com/Labout/log4shell-rmi-pochttps://github.com/lathika-3006/Solar-exploiting-log-4jhttps://github.com/Lavanya2085/solar-exploiting-log4jhttps://github.com/leetxyz/CVE-2021-44228-Advisorieshttps://github.com/LemonCraftRu/JndiRemoverhttps://github.com/lfama/log4j_checkerhttps://github.com/lhotari/log4shell-mitigation-testerhttps://github.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228https://github.com/limxuan/ehir-vuln-enterprise-loginhttps://github.com/LinkMJB/log4shell_scannerhttps://github.com/LiveOverflow/log4shellhttps://github.com/logpresso/CVE-2021-44228-Scannerhttps://github.com/lohanichaten/log4j-cve-2021-44228https://github.com/Loliverte/Log4j-Vulnerabilityhttps://github.com/lonecloud/CVE-2021-44228-Apache-Log4jhttps://github.com/lov3r/cve-2021-44228-log4j-exploitshttps://github.com/lucab85/ansible-role-log4shellhttps://github.com/lucab85/log4j-cve-2021-44228https://github.com/LucasPDiniz/CVE-2021-44228https://github.com/LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228https://github.com/m0rath/detect-log4j-exploitablehttps://github.com/M1ngGod/CVE-2021-44228-Log4j-lookup-Rcehttps://github.com/madCdan/JndiLookuphttps://github.com/MAFO-sec/mi-laboratorio-log4shellhttps://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228https://github.com/MalwareTech/Log4jToolshttps://github.com/manishkanyal/log4j-scannerhttps://github.com/manuel-alvarez-alvarez/log4j-cve-2021-44228https://github.com/many-fac3d-g0d/apache-tomcat-log4jhttps://github.com/MarceloLeite2604/log4j-vulnerabilityhttps://github.com/marcourbano/CVE-2021-44228https://github.com/marklindsey11/-CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVE-2021-44228-https-nvd.https://github.com/marklindsey11/gh-repo-clone-marklindsey11--CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVhttps://github.com/markuman/aws-log4j-mitigationshttps://github.com/maxant/log4j2-CVE-2021-44228https://github.com/maximofernandezriera/CVE-2021-44228https://github.com/mazhar-hassan/log4j-vulnerabilityhttps://github.com/mebibite/log4jhoundhttps://github.com/mergebase/log4j-detectorhttps://github.com/MeterianHQ/log4j-vuln-coverage-checkhttps://github.com/metodidavidovic/log4j-quick-scanhttps://github.com/mgueye3/Log4Shellhttps://github.com/michaelsanford/Log4Shell-Honeypothttps://github.com/MiguelM001/vulescanjndilookuphttps://github.com/Mintimate/log4j2-bugmakerhttps://github.com/mitiga/log4shell-cloud-scannerhttps://github.com/mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraformhttps://github.com/mklinkj/log4j2-testhttps://github.com/mn-io/log4j-spring-vuln-pochttps://github.com/moften/Log4Shellhttps://github.com/momos1337/Log4j-RCEhttps://github.com/moshuum/tf-log4j-aws-pochttps://github.com/MrHarshvardhan/PY-Log4j-RCE-Scannerhttps://github.com/mrlnstk/cve-2021-44228-minecraft-pochttps://github.com/mr-r3b00t/CVE-2021-44228https://github.com/mr-vill4in/log4j-fuzzerhttps://github.com/mschmnet/Log4Shell-demohttps://github.com/mss/log4shell-hotfix-side-effecthttps://github.com/mubix/CVE-2021-44228-Log4Shell-Hasheshttps://github.com/mufeedvh/log4jailhttps://github.com/Muhammad-Ali007/Log4j_CVE-2021-44228https://github.com/municipalparkingservices/CVE-2021-44228-Scannerhttps://github.com/myyxl/cve-2021-44228-minecraft-pochttps://github.com/mzlogin/CVE-2021-44228-Demohttps://github.com/Nanitor/log4fixhttps://github.com/nccgroup/log4j-jndi-be-gonehttps://github.com/neilc1964techned/craready-test-java-vulnshttps://github.com/NikitaPark/Log4Shell-PoC-Applicationhttps://github.com/nikolas-charalambidis/cve-2021-44228https://github.com/Nikolas-Charalambidis/cve-2021-44228https://github.com/nix-xin/vuln4japihttps://github.com/nkoneko/VictimApphttps://github.com/NorthwaveSecurity/log4jcheckhttps://github.com/NS-Sp4ce/Vm4Jhttps://github.com/nu11secur1ty/CVE-2021-44228-VULN-APPhttps://github.com/obscuritylabs/log4shell-poc-labhttps://github.com/ocastel/log4j-shell-pochttps://github.com/Occamsec/log4j-checkerhttps://github.com/OlafHaalstra/log4jcheckhttps://github.com/OopsieWoopsie/mc-log4j-patcherhttps://github.com/ossie-git/log4shell_sentinelhttps://github.com/otaviokr/log4j-2021-vulnerability-studyhttps://github.com/OtisSymbos/CVE-2021-44228-Log4Shell-https://github.com/p3dr16k/log4j-1.2.15-modhttps://github.com/Panyaprach/Prove-CVE-2021-44228https://github.com/paulvkitor/log4shellwithlog4j2_13_3https://github.com/PCMKUIT/CVE-2021-44228---Log4Shell-Analysishttps://github.com/pedrohavay/exploit-CVE-2021-44228https://github.com/perryflynn/find-log4jhttps://github.com/ph0lk3r/anti-jndihttps://github.com/Phineas09/CVE-2021-44228https://github.com/phoswald/sample-ldap-exploithttps://github.com/pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoChttps://github.com/pinaraltinok/Log4Shell-Attackhttps://github.com/pmontesd/log4j-cve-2021-44228https://github.com/PoneyClairDeLune/LogJackFixhttps://github.com/pravin-pp/log4j2-CVE-2021-44228https://github.com/prmawyer/log4shell-vulnerable-apphttps://github.com/probablysecure/Triage-CVE-2021-44228-Log4Shell-Log4j-https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-wordshttps://github.com/puzzlepeaches/Log4jCenterhttps://github.com/puzzlepeaches/Log4jHorizonhttps://github.com/puzzlepeaches/Log4jUnifihttps://github.com/qingtengyun/cve-2021-44228-qingteng-online-patchhttps://github.com/qingtengyun/cve-2021-44228-qingteng-patchhttps://github.com/qw3rtyou/CVE-2021-44228_dockernizehttps://github.com/r00thunter/Log4Shellhttps://github.com/r00thunter/Log4Shell-Scannerhttps://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generatorhttps://github.com/ra890927/Log4Shell-CVE-2021-44228-Demohttps://github.com/racoon-rac/CVE-2021-44228https://github.com/Rainyseason-c/log4j2_CVE-2021-44228https://github.com/rakutentech/jndi-ldap-test-serverhttps://github.com/Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-mainhttps://github.com/razureink/cve-2021-44228-log4shell_rce_reproductionhttps://github.com/recanavar/vuln_spring_log4j2https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCshttps://github.com/redhuntlabs/Log4JHunthttps://github.com/rejupillai/log4j2-hack-springboothttps://github.com/RenYuH/log4j-lookups-vulnerabilityhttps://github.com/rgl/log4j-log4shell-playgroundhttps://github.com/Ricardo354/homelab-CVE-2021-44228https://github.com/Rk-000/Log4j_scan_Advancehttps://github.com/RK800-DEV/apache-log4j-pochttps://github.com/robrankin/cve-2021-44228-waf-testshttps://github.com/rodfer0x80/log4j2-prosecutorhttps://github.com/Rohan-flutterint/CVE-2021-44228_scannerhttps://github.com/romanutti/log4shell-vulnerable-apphttps://github.com/roshanshibu/Odysseushttps://github.com/roticagas/CVE-2021-44228-Demohttps://github.com/roxas-tan/CVE-2021-44228https://github.com/RrUZi/Awesome-CVE-2021-44228https://github.com/rubo77/log4j_checker_betahttps://github.com/rv4l3r3/log4v-vuln-checkhttps://github.com/safeer-accuknox/log4j-shell-pochttps://github.com/saharNooby/log4j-vulnerability-patcher-agenthttps://github.com/sajanapamuditha/Cyber-Attack-Simulation-https://github.com/sanasimran1403-jpg/log4shellhttps://github.com/sandarenu/log4j2-issue-checkhttps://github.com/Saru1718/THM---Solar-exploiting-Log-4jhttps://github.com/sassoftware/loguccinohttps://github.com/scabench/l4j-fp1https://github.com/scabench/l4j-tp1https://github.com/scheibling/py-log4shellscannerhttps://github.com/sdogancesur/log4j_github_repositoryhttps://github.com/sebiboga/jmeter-fix-cve-2021-44228-windowshttps://github.com/sec13b/CVE-2021-44228-POChttps://github.com/SerpilRivas/log4shell-homework9https://github.com/sfr0435122531-ui/-log4shell-labhttps://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCshttps://github.com/shamo0/CVE-2021-44228https://github.com/ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228https://github.com/shivakumarjayaraman/log4jvulnerability-CVE-2021-44228https://github.com/ShlomiRex/log4shell_labhttps://github.com/simonis/Log4jPatchhttps://github.com/sinakeshmiri/log4jScanhttps://github.com/Sma-Das/Log4j-PoChttps://github.com/snapattack/damn-vulnerable-log4j-apphttps://github.com/snatalius/log4j2-CVE-2021-44228-poc-localhttps://github.com/snow0715/log4j-Scan-Burpsuitehttps://github.com/solitarysp/Log4j-CVE-2021-44228https://github.com/Sorrence/CVE-2021-44228https://github.com/sourcegraph/log4j-cve-code-search-resourceshttps://github.com/spasam/log4j2-exploithttps://github.com/sqsec/log4j2_CVE-2021-44228https://github.com/srcporter/CVE-2021-44228https://github.com/s-retlaw/l4s_pochttps://github.com/s-retlaw/l4srshttps://github.com/ssl/scan4log4jhttps://github.com/ssl-user-en/Log4j-Scanner-Exploithttps://github.com/strawhatasif/log4j-testhttps://github.com/stripe/log4j-remediation-toolshttps://github.com/sud0x00/log4j-CVE-2021-44228https://github.com/Sumitpathania03/LOG4J-CVE-2021-44228https://github.com/suniastar/scan-log4shellhttps://github.com/sunnyvale-it/CVE-2021-44228-PoChttps://github.com/Super-Binary/cve-2021-44228https://github.com/suuhm/log4shell4shellhttps://github.com/sysadmin0815/Fix-Log4j-PowershellScripthttps://github.com/tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environmenthttps://github.com/Tai-e/CVE-2021-44228https://github.com/takito1812/log4j-detecthttps://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rcehttps://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploithttps://github.com/tasooshi/horrors-log4shellhttps://github.com/taurusxin/CVE-2021-44228https://github.com/tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228https://github.com/TheArqsz/CVE-2021-44228-PoChttps://github.com/thecyberneh/Log4j-RCE-Exploiterhttps://github.com/thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832https://github.com/TheInterception/Log4J-Simulation-Toolhttps://github.com/thomaspatzke/Log4Pothttps://github.com/threatmonit/Log4j-IOCshttps://github.com/tica506/Siem-queries-for-CVE-2021-44228https://github.com/tieupham267/log4shell-corazahttps://github.com/Timborin0/log4j-dork-scannerhttps://github.com/timothyjxhn/DeliberatelyVulnerableWebApphttps://github.com/tobiasoed/log4j-CVE-2021-44228https://github.com/Toolsec/log4j-scanhttps://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228https://github.com/toramanemre/log4j-rce-detect-waf-bypasshttps://github.com/TotallyNotAHaxxer/f-for-javahttps://github.com/ToxicEnvelope/XSYS-Log4J2Shell-Exhttps://github.com/tpdlshdmlrkfmcla/Log4shellhttps://github.com/TPower2112/Writing-Sample-1https://github.com/trickyearlobe/inspec-log4jhttps://github.com/tuyenee/Log4shellhttps://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-labhttps://github.com/ubitech/cve-2021-44228-rce-pochttps://github.com/uint0/cve-2021-44228-helpershttps://github.com/uint0/cve-2021-44228--spring-hibernatehttps://github.com/unlimitedsola/log4j2-rce-pochttps://github.com/urholaukkarinen/docker-log4shellhttps://github.com/Vaibhav91one/log4shell-cve-labhttps://github.com/VerveIndustrialProtection/CVE-2021-44228-Log4jhttps://github.com/vidrez/Ethical-Hacking-Report-Log4jhttps://github.com/VinniMarcon/Log4j-Updaterhttps://github.com/vino-theva/CVE-2021-44228https://github.com/VNYui/CVE-2021-44228https://github.com/vorburger/Log4j_CVE-2021-44228https://github.com/vulnerable-apps/log4shell-honeypothttps://github.com/Vulnmachines/log4j-cve-2021-44228https://github.com/Vulnmachines/log4jshell_CVE-2021-44228https://github.com/vutiendat323/CVE-2021-44228_Log4Shellhttps://github.com/Wafeeq-Fareed/log4shell-exploitation-labhttps://github.com/wajda/log4shell-test-exploithttps://github.com/WatchGuard-Threat-Lab/log4shell-iocshttps://github.com/wheezysec/CVE-2021-44228-kustohttps://github.com/Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228https://github.com/winnpixie/log4noshellhttps://github.com/wmohamed2033/wmohamed2033.github.iohttps://github.com/Woahd/log4j-urlscannerhttps://github.com/wortell/log4jhttps://github.com/WYSIIWYG/Log4J_0day_RCEhttps://github.com/x1ongsec/CVE-2021-44228-Log4j-JNDIhttps://github.com/xsultan/log4jshieldhttps://github.com/xungzzz/VTI-IOCs-CVE-2021-44228https://github.com/xx-zhang/apache-log4j2-CVE-2021-44228https://github.com/Y0-kan/Log4jShell-Scanhttps://github.com/yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-https://github.com/yanghaoi/CVE-2021-44228_Log4Shellhttps://github.com/YangHyperData/LOGJ4_PocShell_CVE-2021-44228https://github.com/ycdxsb/Log4Shell-CVE-2021-44228-ENVhttps://github.com/yesspider-hacker/log4j-payload-generatorhttps://github.com/yili-soc/vm-homelab-log4shell-assessmenthttps://github.com/y-security/yLog4jhttps://github.com/yuuki1967/CVE-2021-44228-Apache-Log4j-Rcehttps://github.com/ZacharyZcR/CVE-2021-44228https://github.com/zaneef/CVE-2021-44228https://github.com/zhangxvx/Log4j-Rec-CVE-2021-44228https://github.com/zlepper/CVE-2021-44228-Test-Serverhttps://github.com/zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Servicehttps://github.com/zzzz0317/log4j2-vulnerable-spring-apphttps://www.exploit-db.com/exploits/50590https://www.exploit-db.com/exploits/50592

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High