Miggo Logo

CVE-2021-4104:
Log4j JMSAppender Deserialization Vulnerability

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.98666%
Published
12/14/2021
Updated
12/22/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
log4j:log4jmaven>= 1.2.0, <= 1.2.17
org.zenframework.z8.dependencies.commons:log4j-1.2.17maven<= 2.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

JMS*pp*n**r in Lo**j *.* is vuln*r**l* to **s*ri*liz*tion o* untrust** **t* w**n t** *tt**k*r **s writ* ****ss to t** Lo**j *on*i*ur*tion. T** *tt**k*r **n provi** Topi**in*in*N*m* *n* Topi**onn**tion***tory*in*in*N*m* *on*i*ur*tions **usin* JMS*pp*n

Reasoning

No *n*lysis *v*il**l*