CVE-2021-45105
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
What Should I Do?
Fix in Your Next Sprint
This vulnerability has a 71.36% chance of being exploited within 30 days.
Summary
Remediation
Upgrade to the fixed version using your package manager.
<!-- Update pom.xml dependency version to 2.12.3 for org.apache.logging.log4j:log4j-core -->
<!-- Update pom.xml dependency version to 2.3.1 for org.apache.logging.log4j:log4j-core -->
<!-- Update pom.xml dependency version to 1.11.12 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 1.10.9 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 1.9.2 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 2.0.13 for org.ops4j.pax.logging:pax-logging-log4j2 -->
<!-- Update pom.xml dependency version to 2.17.0 for org.apache.logging.log4j:log4j-core -->
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (7)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| org.apache.logging.log4j:log4j-core | Maven | 2.10.0, 2.11.0, 2.11.1, 2.11.2 (+15 more) | 2.12.3 |
| org.apache.logging.log4j:log4j-core | Maven | 2.0, 2.0-alpha1, 2.0-alpha2, 2.0-beta1 (+15 more) | 2.3.1 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.11.0, 1.11.1, 1.11.10, 1.11.11 (+8 more) | 1.11.12 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.10.0, 1.10.1, 1.10.2, 1.10.3 (+5 more) | 1.10.9 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 1.8.0, 1.8.1, 1.8.2, 1.8.3 (+6 more) | 1.9.2 |
| org.ops4j.pax.logging:pax-logging-log4j2 | Maven | 2.0.0, 2.0.1, 2.0.10, 2.0.11 (+9 more) | 2.0.13 |
| org.apache.logging.log4j:log4j-core | Maven | 2.13.0, 2.13.1, 2.13.2, 2.13.3 (+4 more) | 2.17.0 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-20Improper Input ValidationMITRE
- CWE-674
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 8.6 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-45105ADVISORY
- https://www.zerodayinitiative.com/advisories/ZDI-21-1541WEB
- https://www.oracle.com/security-alerts/cpujul2022.htmlWEB
- https://www.oracle.com/security-alerts/cpujan2022.htmlWEB
- https://www.oracle.com/security-alerts/cpuapr2022.htmlWEB
- https://www.kb.cert.org/vuls/id/930724WEB
- https://www.debian.org/security/2021/dsa-5024WEB
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdWEB
- https://security.netapp.com/advisory/ntap-20211218-0001WEB
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdWEB
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032WEB
- https://logging.apache.org/log4j/2.x/security.htmlWEB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJWEB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCYWEB
- https://lists.debian.org/debian-lts-announce/2021/12/msg00017.htmlWEB
- https://cert-portal.siemens.com/productcert/pdf/ssa-501673.pdfWEB
- https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfWEB
- https://www.openwall.com/lists/oss-security/2021/12/19/1WEB
Frequently Asked Questions
- What is CVE-2021-45105?
- Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.6/10).
- How do I check if my project is affected by CVE-2021-45105?
- CVE-2021-45105 affects org.apache.logging.log4j:log4j-core and org.ops4j.pax.logging:pax-logging-log4j2. It has a 71.4% probability of exploitation within 30 days (EPSS score). Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2021-45105 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
Also Known As
Related CVEs
- CVE-2021-45046CRITICAL
Incomplete fix for Apache Log4j vulnerability
- CVE-2021-44228CRITICAL
Remote code injection in Log4j
- CVE-2026-64679HIGH
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
- CVE-2026-63135HIGH
YOURLS has stored XSS in referrer statistics chart via crafted Referer header
- CVE-2026-54178HIGH
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
- CVE-2026-54182HIGH
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
- CVE-2021-44832MEDIUM
Improper Input Validation and Injection in Apache Log4j2
- CVE-2025-68161MEDIUM
Apache Log4j does not verify the TLS hostname in its Socket Appender
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies