
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. The vulnerability was discovered in December 2021 and fixed in Log4j versions 2.17.0, 2.12.3, and 2.3.1 (Apache Log4j).
The vulnerability occurs when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}). Attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. The vulnerability has a CVSS v3.1 base score of 5.9 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Only the log4j-core JAR file is impacted by this vulnerability (Apache Log4j, NVD).
When successfully exploited, this vulnerability can lead to a denial of service (DoS) condition through uncontrolled recursion, causing the application to crash with a StackOverflowError. This affects the availability of systems using vulnerable Log4j versions (Apache Log4j).
The vulnerability requires an attacker to have control over Thread Context Map (MDC) input data and the target system must be using a non-default Pattern Layout with Context Lookups. The attack complexity is considered high, but no authentication is required for remote exploitation (NVD).
Users should upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later). Alternatively, in PatternLayout configuration, replace Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc, or %MDC). Another option is to remove references to Context Lookups where they originate from external sources such as HTTP headers or user input (Apache Log4j).
The vulnerability was independently discovered by multiple researchers including Hideki Okamoto of Akamai Technologies, Guy Lederfein of Trend Micro Research working with Trend Micro's Zero Day Initiative, and another anonymous vulnerability researcher. Major vendors like Cisco, Oracle, and VMware issued advisories and patches for their affected products (Apache Log4j).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"