CVE-2021-45046
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9
- EPSS
- 100.0% 백분위 100.0% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.05.22
- 공개일
- 2021.12.15
CISA KEV에 등록된 실제 악용 확인 취약점
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and...
공급사 Apache
제품 Log4j2
영향 버전 Apache Log4j2, >= 2.0.1 < 2.12.2, >= 2.13.0 < 2.16.0, 2.0, < 2019.1, 2019.1, 4.0, 4.1, 4.2, 5.0, 5.1, < 2021-12-13, 3.1, 8.5, 8.6, 8.7, 9.0, 3.7, 3.8, < 8.6.2j-398
수정 버전 2.12.2, 2.16.0, 2019.1, 2021-12-13, 8.6.2j-398, 2021-12-11, 2020, 4.70, 2.30, 10.0.12, 2.7.0
Apply updates per vendor instructions.
조치 기한: 2023.05.22CVSS 벡터 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE CWE-917
KEV 등록일 2023.05.01
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046
EPSS 데이터 기준일 2026.06.27