目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-44228— Apache Log4j 代码问题漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache Log4j2
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Apache Log4J 存在代码问题漏洞,攻击者可设计一个数据请求发送给使用 Apache Log4j工具的服务器,当该请求被打印成日志时就会触发远程代码执行。

AI 预测 10.0 利用难度: 极易 KEV · 勒索软件 EPSS 100.00% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-44228 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
来源: CVE Program / CVE List V5
Vulnerability Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
来源: CVE Program / CVE List V5
Vulnerability Title
Apache Log4j 代码问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Apache Log4J 存在代码问题漏洞,攻击者可设计一个数据请求发送给使用 Apache Log4j工具的服务器,当该请求被打印成日志时就会触发远程代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache Log4j2 2.0-beta9 ~ log4j-core* -

二、漏洞 CVE-2021-44228 的公开POC

# POC 描述 源链接 神龙链接
1 Apache Log4j 远程代码执行 https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce POC详情
2 Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2 https://github.com/Glease/Healer POC详情
3 This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch https://github.com/jacobtread/L4J-Vuln-Patch POC详情
4 Remote Code Injection In Log4j https://github.com/jas502n/Log4j2-CVE-2021-44228 POC详情
5 Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept POC详情
6 一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense. https://github.com/boundaryx/cloudrasp-log4j2 POC详情
7 Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser. https://github.com/dbgee/CVE-2021-44228 POC详情
8 A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer) https://github.com/CreeperHost/Log4jPatcher POC详情
9 CVE-2021-44228 fix https://github.com/DragonSurvivalEU/RCE POC详情
10 Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process https://github.com/simonis/Log4jPatch POC详情
11 A small server for verifing if a given java program is succeptibel to CVE-2021-44228 https://github.com/zlepper/CVE-2021-44228-Test-Server POC详情
12 Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228). https://github.com/christophetd/log4shell-vulnerable-app POC详情
13 A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers. https://github.com/NorthwaveSecurity/log4jcheck POC详情
14 Vulnerable to CVE-2021-44228. trustURLCodebase is not required. https://github.com/nkoneko/VictimApp POC详情
15 Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell https://github.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228 POC详情
16 Apache Log4j2 RCE( CVE-2021-44228)验证环境 https://github.com/1in9e/Apache-Log4j2-RCE POC详情
17 vulnerability POC https://github.com/KosmX/CVE-2021-44228-example POC详情
18 Vulnerability CVE-2021-44228 checker https://github.com/greymd/CVE-2021-44228 POC详情
19 Hashes for vulnerable LOG4J versions https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes POC详情
20 CVE-2021-44228 server-side fix for minecraft servers. https://github.com/OopsieWoopsie/mc-log4j-patcher POC详情
21 None https://github.com/wheez-y/CVE-2021-44228-kusto POC详情
22 Mitigation for Log4Shell Security Vulnerability CVE-2021-44228 https://github.com/izzyacademy/log4shell-mitigation POC详情
23 log4shell sample application (CVE-2021-44228) https://github.com/0xst4n/CVE-2021-44228-poc POC详情
24 Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading https://github.com/takito1812/log4j-detect POC详情
25 Java agent that disables Apache Log4J's JNDI Lookup. Fixes CVE-2021-44228, aka "Log4Shell." https://github.com/winnpixie/log4noshell POC详情
26 CVE-2021-44228 DFIR Notes https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes POC详情
27 🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words POC详情
28 A Proof-Of-Concept for the CVE-2021-44228 vulnerability. https://github.com/kozmer/log4j-shell-poc POC详情
29 Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit) https://github.com/alexandreroman/cve-2021-44228-workaround-buildpack POC详情
30 Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam https://github.com/Adikso/minecraft-log4j-honeypot POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-44228 的情报信息

请登录查看更多情报信息。

CVE-2021-44228 厂商安全公告 (12)

CVE-2021-44228 公开利用代码 (13)

CVE-2021-44228 邮件列表归档 (13)

CVE-2021-44228 安全博客文章 (1)

CVE-2021-44228 其他参考 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2021-44228

匿名用户
2026-03-11 15:13:48

Hello team! I came across a 162 great website that I think you should dive into. This tool is packed with a lot of useful information that you might find interesting. It has everything you could possibly need, so be sure to give it a visit! [url=https://alternativeway.net/why-are-airports-so-confusing-the-psychology-of-terminal-design/]https://alternativeway.net/why-are-airports-so-confusing-the-psychology-of-terminal-design/[/url] Furthermore don't neglect, everyone, which you constantly may inside this particular piece find solutions to address the most most confusing questions. The authors attempted — explain the complete data via the most most easy-to-grasp way.


发表评论