CVE-2021-44832
Improper Input Validation and Injection in Apache Log4j2
What Should I Do?
Fix Within 2-4 Weeks
Moderate exploitation risk (53.59% probability in 30 days). Schedule remediation soon.
Summary
Remediation
Upgrade to the fixed version using your package manager.
<!-- Update pom.xml dependency version to 1.10.9 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 1.9.2 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 1.11.13 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 2.0.14 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 2.17.1 for org.apache.logging.log4j:log4j-core -->
<!-- Update pom.xml dependency version to 2.12.4 for org.apache.logging.log4j:log4j-core -->
<!-- Update pom.xml dependency version to 2.3.2 for org.apache.logging.log4j:log4j-core -->
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (7)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.10.0, 1.10.1, 1.10.2, 1.10.3 (+5 more) | 1.10.9 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.8.0, 1.8.1, 1.8.2, 1.8.3 (+6 more) | 1.9.2 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.11.0, 1.11.1, 1.11.10, 1.11.11 (+9 more) | 1.11.13 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 2.0.0, 2.0.1, 2.0.10, 2.0.11 (+10 more) | 2.0.14 |
| org.apache.logging.log4j:log4j-core | Maven | 2.13.0, 2.13.1, 2.13.2, 2.13.3 (+5 more) | 2.17.1 |
| org.apache.logging.log4j:log4j-core | Maven | 2.10.0, 2.11.0, 2.11.1, 2.11.2 (+16 more) | 2.12.4 |
| org.apache.logging.log4j:log4j-core | Maven | 2.0, 2.0-beta7, 2.0-beta8, 2.0-beta9 (+8 more) | 2.3.2 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-20Improper Input ValidationMITRE
- CWE-74
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 6.6 score means for each attack dimension.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-44832ADVISORY
- https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdfWEB
- https://github.com/apache/logging-log4j2PACKAGE
- https://issues.apache.org/jira/browse/LOG4J2-3293WEB
- https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143WEB
- https://lists.debian.org/debian-lts-announce/2021/12/msg00036.htmlWEB
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRAWEB
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFCWEB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ7T6F65MRAWEB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHMMPQNVKGFCWEB
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdWEB
- https://security.netapp.com/advisory/ntap-20220104-0001WEB
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdWEB
- https://www.oracle.com/security-alerts/cpuapr2022.htmlWEB
- https://www.oracle.com/security-alerts/cpujan2022.htmlWEB
- https://www.oracle.com/security-alerts/cpujul2022.htmlWEB
- https://www.openwall.com/lists/oss-security/2021/12/28/1WEB
Frequently Asked Questions
- What is CVE-2021-44832?
- Improper Input Validation and Injection in Apache Log4j2 This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 6.6/10).
- How do I check if my project is affected by CVE-2021-44832?
- CVE-2021-44832 affects org.ops4j.pax.logging:pax-logging-log4j2 and org.apache.logging.log4j:log4j-core. It has a 53.6% probability of exploitation within 30 days (EPSS score). Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2021-44832 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation requires specific conditions or has limited impact. Remediate within weeks.
Also Known As
Related CVEs
- CVE-2021-45046CRITICAL
Incomplete fix for Apache Log4j vulnerability
- CVE-2021-44228CRITICAL
Remote code injection in Log4j
- CVE-2021-45105HIGH
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
- CVE-2026-62909MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
- CVE-2026-62902MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
- CVE-2026-61807MEDIUM
Snipe-IT: Stored DOM XSS via table selected-count IDs
- CVE-2026-62899MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
- CVE-2025-68161MEDIUM
Apache Log4j does not verify the TLS hostname in its Socket Appender
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies