Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2021-45046

Apache | Log4j2Added 2023-05-01Remediation Deadline 2023-05-22Active Ransomware Campaign

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-917

References