CVE-2021-4104 (CNNVD-202112-1011)

HIGH
中文标题:
Apache Log4j 代码问题漏洞
英文标题:
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
CVSS分数: 7.5
发布时间: 2021-12-14 00:00:00
漏洞类型: 代码问题
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Apache Log4j 1.2存在代码问题漏洞,攻击者可利用该漏洞通过JMSApender反序列化来运行代码。

英文描述:

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CWE类型:
CWE-502
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Apache Software Foundation Apache Log4j 1.x Apache Log4j 1.2 1.2.x - - cpe:2.3:a:apache_software_foundation:apache_log4j_1.x:apache_log4j_1.2_1.2.x:*:*:*:*:*:*:*
apache log4j 1.2 - - cpe:2.3:a:apache:log4j:1.2:*:*:*:*:*:*:*
fedoraproject fedora 35 - - cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
redhat codeready_studio 12.0 - - cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*
redhat integration_camel_k - - - cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:*
redhat integration_camel_quarkus - - - cpe:2.3:a:redhat:integration_camel_quarkus:-:*:*:*:*:*:*:*
redhat jboss_a-mq 6.0.0 - - cpe:2.3:a:redhat:jboss_a-mq:6.0.0:*:*:*:*:*:*:*
redhat jboss_a-mq 7 - - cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*
redhat jboss_a-mq_streaming - - - cpe:2.3:a:redhat:jboss_a-mq_streaming:-:*:*:*:*:*:*:*
redhat jboss_data_grid 7.0.0 - - cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
redhat jboss_data_virtualization 6.0.0 - - cpe:2.3:a:redhat:jboss_data_virtualization:6.0.0:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 6.0.0 - - cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 7.0 - - cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*
redhat jboss_fuse 6.0.0 - - cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
redhat jboss_fuse 7.0.0 - - cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
redhat jboss_fuse_service_works 6.0 - - cpe:2.3:a:redhat:jboss_fuse_service_works:6.0:*:*:*:*:*:*:*
redhat jboss_operations_network 3.0 - - cpe:2.3:a:redhat:jboss_operations_network:3.0:*:*:*:*:*:*:*
redhat jboss_web_server 3.0 - - cpe:2.3:a:redhat:jboss_web_server:3.0:*:*:*:*:*:*:*
redhat openshift_application_runtimes - - - cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
redhat openshift_container_platform 4.6 - - cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
redhat openshift_container_platform 4.7 - - cpe:2.3:a:redhat:openshift_container_platform:4.7:*:*:*:*:*:*:*
redhat openshift_container_platform 4.8 - - cpe:2.3:a:redhat:openshift_container_platform:4.8:*:*:*:*:*:*:*
redhat process_automation 7.0 - - cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
redhat single_sign-on 7.0 - - cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
redhat software_collections - - - cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
redhat enterprise_linux 6.0 - - cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
redhat enterprise_linux 7.0 - - cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
redhat enterprise_linux 8.0 - - cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
oracle advanced_supply_chain_planning 12.1 - - cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:*
oracle advanced_supply_chain_planning 12.2 - - cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:*
oracle business_intelligence 5.9.0.0.0 - - cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*
oracle business_intelligence 12.2.1.3.0 - - cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
oracle business_intelligence 12.2.1.4.0 - - cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
oracle business_process_management_suite 12.2.1.3.0 - - cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
oracle business_process_management_suite 12.2.1.4.0 - - cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
oracle communications_eagle_ftp_table_base_retrieval 4.5 - - cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:*
oracle communications_messaging_server 8.1 - - cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
oracle communications_network_integrity 7.3.6 - - cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
oracle communications_offline_mediation_controller * - - cpe:2.3:a:oracle:communications_offline_mediation_controller:*:*:*:*:*:*:*:*
oracle communications_offline_mediation_controller 12.0.0.5.0 - - cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.5.0:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.3.4 - - cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.3.5 - - cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.4.1 - - cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
oracle communications_unified_inventory_management 7.4.2 - - cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*
oracle e-business_suite_cloud_manager_and_cloud_backup_module 2.2.1.1.1 - - cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:*
oracle enterprise_manager_base_platform 13.4.0.0 - - cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*
oracle enterprise_manager_base_platform 13.5.0.0 - - cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*
oracle financial_services_revenue_management_and_billing_analytics 2.7.0.0 - - cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:*
oracle financial_services_revenue_management_and_billing_analytics 2.7.0.1 - - cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:*
oracle financial_services_revenue_management_and_billing_analytics 2.8.0.0 - - cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:*
oracle fusion_middleware_common_libraries_and_tools 12.2.1.4.0 - - cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*
oracle goldengate - - - cpe:2.3:a:oracle:goldengate:-:*:*:*:*:*:*:*
oracle healthcare_data_repository 8.1.0 - - cpe:2.3:a:oracle:healthcare_data_repository:8.1.0:*:*:*:*:*:*:*
oracle hyperion_data_relationship_management * - - cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:*
oracle hyperion_infrastructure_technology * - - cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:*
oracle identity_management_suite 12.2.1.3.0 - - cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
oracle identity_management_suite 12.2.1.4.0 - - cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
oracle jdeveloper 12.2.1.3.0 - - cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*
oracle mysql_enterprise_monitor * - - cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
oracle retail_allocation 14.1.3.2 - - cpe:2.3:a:oracle:retail_allocation:14.1.3.2:*:*:*:*:*:*:*
oracle retail_allocation 15.0.3.1 - - cpe:2.3:a:oracle:retail_allocation:15.0.3.1:*:*:*:*:*:*:*
oracle retail_allocation 16.0.3 - - cpe:2.3:a:oracle:retail_allocation:16.0.3:*:*:*:*:*:*:*
oracle retail_allocation 19.0.1 - - cpe:2.3:a:oracle:retail_allocation:19.0.1:*:*:*:*:*:*:*
oracle retail_extract_transform_and_load 13.2.5 - - cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.5:*:*:*:*:*:*:*
oracle stream_analytics - - - cpe:2.3:a:oracle:stream_analytics:-:*:*:*:*:*:*:*
oracle timesten_grid - - - cpe:2.3:a:oracle:timesten_grid:-:*:*:*:*:*:*:*
oracle tuxedo 12.2.2.0.0 - - cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:*
oracle utilities_testing_accelerator 6.0.0.1.1 - - cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*:*:*:*:*:*
oracle utilities_testing_accelerator 6.0.0.2.2 - - cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:*:*:*:*:*:*
oracle utilities_testing_accelerator 6.0.0.3.1 - - cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:*:*:*:*:*:*
oracle weblogic_server 12.2.1.3.0 - - cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
oracle weblogic_server 12.2.1.4.0 - - cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
oracle weblogic_server 14.1.1.0.0 - - cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
VU#930724 third-party-advisory
cve.org
访问
[oss-security] 20220118 CVE-2022-23302: Deserialization of untrusted data in JMSSink in Apache Log4j 1.x mailing-list
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
GLSA-202209-02 vendor-advisory
cve.org
访问
GLSA-202310-16 vendor-advisory
cve.org
访问
GLSA-202312-02 vendor-advisory
cve.org
访问
GLSA-202312-04 vendor-advisory
cve.org
访问
CVSS评分详情
7.5
HIGH
CVSS向量: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS版本: 3.1
机密性
HIGH
完整性
HIGH
可用性
HIGH
时间信息
发布时间:
2021-12-14 00:00:00
修改时间:
2024-08-03 17:16:04
创建时间:
2025-11-11 15:37:02
更新时间:
2025-11-11 15:57:01
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2021-4104 2025-11-11 15:21:12 2025-11-11 07:37:02
NVD nvd_CVE-2021-4104 2025-11-11 14:57:46 2025-11-11 07:45:20
CNNVD cnnvd_CNNVD-202112-1011 2025-11-11 15:10:46 2025-11-11 07:57:01
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:57:01
vulnerability_type: 未提取 → 代码问题; cnnvd_id: 未提取 → CNNVD-202112-1011; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 代码问题
  • cnnvd_id: 未提取 -> CNNVD-202112-1011
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:45:20
severity: SeverityLevel.MEDIUM → SeverityLevel.HIGH; cvss_score: 未提取 → 7.5; cvss_vector: NOT_EXTRACTED → CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H; cvss_version: NOT_EXTRACTED → 3.1; affected_products_count: 1 → 73; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
  • cvss_score: 未提取 -> 7.5
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • cvss_version: NOT_EXTRACTED -> 3.1
  • affected_products_count: 1 -> 73
  • data_sources: ['cve'] -> ['cve', 'nvd']