Log4Shell: JNDI lookup injection in Log4j 2
User-controlled strings reaching a Log4j 2 logging call trigger a JNDI lookup, giving remote code execution.
- Severity
- 10.0critical
- Vendor
- Apache
- Disclosed
- 10 Dec 2021
- Affected
- Log4j 2.0-beta9 through 2.14.1
CVSS breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Analysis
Placeholder analysis — replace before publishing.