Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-44228— Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Quick assessment

Affected
Apache Software Foundation Apache Log4j2
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Apache Log4J 存在代码问题漏洞,攻击者可设计一个数据请求发送给使用 Apache Log4j工具的服务器,当该请求被打印成日志时就会触发远程代码执行。

AI Predicted 10.0 Difficulty: Trivial KEV · Ransomware EPSS 100.00% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-44228

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Log4j 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Apache Log4J 存在代码问题漏洞,攻击者可设计一个数据请求发送给使用 Apache Log4j工具的服务器,当该请求被打印成日志时就会触发远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Log4j2 2.0-beta9 ~ log4j-core* -

II. Public POCs for CVE-2021-44228

# POC Description Source Link Shenlong Link
1 Apache Log4j 远程代码执行 https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce POC Details
2 Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2 https://github.com/Glease/Healer POC Details
3 This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch https://github.com/jacobtread/L4J-Vuln-Patch POC Details
4 Remote Code Injection In Log4j https://github.com/jas502n/Log4j2-CVE-2021-44228 POC Details
5 Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept POC Details
6 一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense. https://github.com/boundaryx/cloudrasp-log4j2 POC Details
7 Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser. https://github.com/dbgee/CVE-2021-44228 POC Details
8 A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer) https://github.com/CreeperHost/Log4jPatcher POC Details
9 CVE-2021-44228 fix https://github.com/DragonSurvivalEU/RCE POC Details
10 Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process https://github.com/simonis/Log4jPatch POC Details
11 A small server for verifing if a given java program is succeptibel to CVE-2021-44228 https://github.com/zlepper/CVE-2021-44228-Test-Server POC Details
12 Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228). https://github.com/christophetd/log4shell-vulnerable-app POC Details
13 A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers. https://github.com/NorthwaveSecurity/log4jcheck POC Details
14 Vulnerable to CVE-2021-44228. trustURLCodebase is not required. https://github.com/nkoneko/VictimApp POC Details
15 Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell https://github.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228 POC Details
16 Apache Log4j2 RCE( CVE-2021-44228)验证环境 https://github.com/1in9e/Apache-Log4j2-RCE POC Details
17 vulnerability POC https://github.com/KosmX/CVE-2021-44228-example POC Details
18 Vulnerability CVE-2021-44228 checker https://github.com/greymd/CVE-2021-44228 POC Details
19 Hashes for vulnerable LOG4J versions https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes POC Details
20 CVE-2021-44228 server-side fix for minecraft servers. https://github.com/OopsieWoopsie/mc-log4j-patcher POC Details
21 None https://github.com/wheez-y/CVE-2021-44228-kusto POC Details
22 Mitigation for Log4Shell Security Vulnerability CVE-2021-44228 https://github.com/izzyacademy/log4shell-mitigation POC Details
23 log4shell sample application (CVE-2021-44228) https://github.com/0xst4n/CVE-2021-44228-poc POC Details
24 Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading https://github.com/takito1812/log4j-detect POC Details
25 Java agent that disables Apache Log4J's JNDI Lookup. Fixes CVE-2021-44228, aka "Log4Shell." https://github.com/winnpixie/log4noshell POC Details
26 CVE-2021-44228 DFIR Notes https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes POC Details
27 🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words POC Details
28 A Proof-Of-Concept for the CVE-2021-44228 vulnerability. https://github.com/kozmer/log4j-shell-poc POC Details
29 Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit) https://github.com/alexandreroman/cve-2021-44228-workaround-buildpack POC Details
30 Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam https://github.com/Adikso/minecraft-log4j-honeypot POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-44228

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-44228 (12)

Exploits & Public PoCs for CVE-2021-44228 (13)

Mailing List Discussions for CVE-2021-44228 (13)

Security Blog Posts for CVE-2021-44228 (1)

Other References for CVE-2021-44228 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2021-44228

Anonymous User
2026-03-11 15:13:48

Hello team! I came across a 162 great website that I think you should dive into. This tool is packed with a lot of useful information that you might find interesting. It has everything you could possibly need, so be sure to give it a visit! [url=https://alternativeway.net/why-are-airports-so-confusing-the-psychology-of-terminal-design/]https://alternativeway.net/why-are-airports-so-confusing-the-psychology-of-terminal-design/[/url] Furthermore don't neglect, everyone, which you constantly may inside this particular piece find solutions to address the most most confusing questions. The authors attempted — explain the complete data via the most most easy-to-grasp way.


Leave a comment