Background
Apache Log4j2 is a ubiquitous library used by millions for Java applications; the library is part of the Apache Software Foundation’s Apache Logging Services project. The vulnerability CVE-2021-44228, disclosed on December 9, 2021, allows for remote code execution against users with certain standard configurations in prior versions of Log4j 2 as of Log4j 2.0.15. Since the release of 0-day vulnerability (CVE-2021-44228) in Apache Log4j 2, and its public exploit on GitHub, it has taken the security teams by storm. This vulnerability is actively being exploited in the wild.
Many devices identified being affected by it (Apple, Vmware v sphere, logrythm, and elastic to name a few). In addition to this, security researchers all over the world are finding more and more ways to bypass the detection techniques and to successfully exploit this weakness in the Log4j library.
The default configuration of Apache Log4j supports JNDI (Java Naming and Directory Interface) lookups that can execute arbitrary code provided by remote services such as LDAP, RMI, and DNS.
What is Log4j?
Log4j is one of the many building blocks that are used in the creation of modern software. It is used by many organizations to do a common but vital job. This is called a ‘software library’.
Log4j is used by developers to keep track of what happens in their software applications or online services. It’s basically a huge journal of the activity of a system or application. This activity is called ‘logging’ and it’s used by developers to keep an eye out for problems for users.
Threat Overview:
Last week, a vulnerability was found in Log4j, an open-source logging library commonly used by apps and services across the internet. A remote, unauthenticated attacker with the ability to log specially crafted messages can cause Log4j to connect to a service controlled by the attacker to download and execute arbitrary code.
If left unfixed, attackers can break into systems, steal passwords and logins, extract data, and infect networks with malicious software.
Log4j is used worldwide across software applications and online services, and the vulnerability requires very little expertise to exploit. This makes Log4shell potentially the most severe computer vulnerability in years.
Impacted Versions:
2.0 <= Apache log4j <= 2.15.0-rc1
Log4j 1.x
Log4j 1.x mitigation: Log4j 1.x does not have Lookups so the risk is lower. Applications using Log4j 1.x are only vulnerable to this attack when they use JNDI in their configuration. A separate CVE (CVE-2021-4104) has been filed for this vulnerability.
To mitigate: audit your logging configuration to ensure it has no JMSAppender configured. Log4j 1.x configurations without JMSAppender are not impacted by this vulnerability.
log4j-core
Note that only the log4j-core JAR file is impacted by this vulnerability. Applications using only the log4j-api JAR file without the log4j-core JAR file are not impacted by this vulnerability.
Associated CVEs and CVSS
| CVE ID | Vulnerability Type(s) | Publish Date | Update Date | Score | Access | Complexity | Authentication | Conf. | Integ. | Avail. |
|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2021-45105 | DoS | 18-12-21 | 22-12-21 | 5 | Remote | Low | Not required | None | None | Partial |
| CVE-2021-45046 | Exec Code +Info | 14-12-21 | 22-12-21 | 5.1 | Remote | High | Not required | Partial | Partial | Partial |
| CVE-2021-44228 | Exec Code | 10-12-21 | 20-12-21 | 9.3 | Remote | Medium | Not required | Complete | Complete | Complete |
| CVE-2021-4104 | Exec Code | 14-12-21 | 21-12-21 | 6.8 | Remote | Medium | Not required | Partial | Partial | Partial |
Overview of Found Vulnerabilities and Updates:

Latest Update on Log4j CVEs :
On 18-Dec-2021, Apache Software Foundation provided another update to log4j (version 2.17.0) to address a new CVE-2021-45105. Contrast recommends using this most secure version.
The latest 2.17.0 update is the latest, fixing the results.
- Log4j 2.16.0 is vulnerable to CVE-2021-45105, from December 16.
- Log4j 2.15.0 is vulnerable to CVE-2021-45046, from December 14.
- Log4j 2.14 and below are CVE-20210-44228(log4shell), from December 9.
List of Vulnerable Softwares
The Log4j library is frequently used in software and the links below provide a non-exhaustive lists of vulnerable products:
- Github – CISA Log4j vulnerability guidance
- Github – NCSC-NL Log4j overview related software
- Mvnrepository – Artifacts using Apache Log4j Core
Action Plan

In Log4j 2.12.2 (for Java 7) and 2.16.0 (for Java 8 or later) the message lookups feature has been completely removed. In addition, JNDI is disabled by default and other default configuration settings are modified to mitigate CVE-2021-44228 and CVE-2021-45046.
For Log4j 1, remove the JMSAppender class or do not configure it. Log4j 1 is not supported and likely contains unfixed bugs and vulnerabilities such as CVE-2019-17571.
- To know if you are vulnerable to it or not?
The first step in your action plan is to identify how many of your assets are vulnerable to it, since you can only patch the devices/tools/software w