Miggo Logo

CVE-2021-44832:
Improper Input Validation and Injection in Apache Log4j2

6.6

CVSS Score
3.1

Basic Information

EPSS Score
0.9738%
Published
1/4/2022
Updated
1/27/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.logging.log4j:log4j-coremaven>= 2.0-beta7, < 2.3.22.3.2
org.apache.logging.log4j:log4j-coremaven>= 2.4, < 2.12.42.12.4
org.apache.logging.log4j:log4j-coremaven>= 2.13.0, < 2.17.12.17.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*p**** Lo**j* v*rsions *.*-**t** t*rou** *.**.* (*x*lu*in* s**urity *ix r*l**s*s *.*.* *n* *.**.*) *r* vuln*r**l* to *n *tt**k w**r* *n *tt**k*r wit* p*rmission to mo*i*y t** lo**in* *on*i*ur*tion *il* **n *onstru*t * m*li*ious *on*i*ur*tion usin* *

Reasoning

No *n*lysis *v*il**l*