S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-45046 Scanner

CVE-2021-45046 scanner - Remote Code Execution (RCE) vulnerability in Apache Log4j

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-45046
9.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Log4jby Apache Software Foundation
AFFECTED< 2.16.0SAFE ✓≥ 2.16.0
Updated Aug 21, 2026View on NVD →
Detail

Apache Log4j is a popular logging utility in the Java-based application development world. It allows developers to customize the logging output in their applications, making it easier to identify and debug issues. This tool is widely used in enterprise-level Java applications and has become an essential component of many software projects.

However, recently, a severe security vulnerability was detected in Apache Log4j, titled CVE-2021-45046. It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This vulnerability could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data using a JNDI Lookup pattern, resulting in information leakage and remote code execution in some environments and local code execution in all environments.

When exploited, CVE-2021-45046 could lead to disastrous consequences. Hackers could gain complete control of the victim's system and access sensitive information such as usernames, passwords, and intellectual property. The attacker could also use the compromised system to launch further attacks, causing even more harm. Therefore, it is essential to protect systems against this vulnerability.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a host of security tools such as vulnerability scanners, threat intelligence, and penetration testing, making it easier for organizations to detect and prevent cybersecurity threats. With s4e.io, you can stay ahead of the game and keep your systems secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Upgrade Log4j to version 2.16.0 (Java 8) or 2.12.2 (Java 7).
  • Disable Pattern Layouts that contain user-controllable inputs.
  • Disable JNDI functionality.
  • Implement proper input validation and sanitization in logging-related code.
  • Keep an eye on updates and security alerts related to Apache Log4j.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-45046 scanner - Remote Code Execution (RCE) vulnerability in Apache Log4j | S4E