Uploaded image for project: 'Log4j 2'
  1. Log4j 2
  2. LOG4J2-3262

Log4j 2.x mitigations for CVE-45046 is insufficient

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • None
    • Documentation

    Description

      The mitigation steps provided for CVE-2021-45046 for those who cannot upgrade to 2.16, seems insufficient. The current description for CVE-2021-45046 says it includes attacks using non-default Pattern Layout with a Context Lookup in the configuration.

      The removal of JNDILookup class file isn't the only solution to curb this issue because the lookup still occurs when the config is loaded. 

      Hence the mitigation steps must include the removal of references to context lookups where the data comes from ThreadContext or from external sources at runtime. (similar to the one provided for CVE-2021-45105 or the same can be included here too)

      Attachments

        Activity

          People

            Unassigned Unassigned
            sivakumarsivaprahasam Sivakumar Sivaprahasam
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: