GHSA-8489-44mv-ggj8

    Dashboard / Vulnerabilities / GHSA-8489-44mv-ggj8

    GHSA-8489-44mv-ggj8

    Published: 4 Jan 2022Last Modified: 9 Jun 2026

    Summary: Improper Input Validation and Injection in Apache Log4j2

    Details: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to an attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use. This issue does not impact default configurations of Log4j2 and requires an attacker to have control over the Log4j2 configuration, which reduces the likelihood of being exploited.

    Affected packages

    Package

    Name: org.apache.logging.log4j:log4j-core

    Purl: pkg:maven/org.apache.logging.log4j/log4j-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.0-beta7
    Fixed -2.3.2

    Affected versions

    2.0
    2.0.1
    2.0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8489-44mv-ggj8 | CVE-DB