HIGH

CVE-2021-4104

CVSS v3

7.5

HIGH

EPSS Score

72.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Technical details

Published
12/14/2021

Frequently asked questions

What is CVE-2021-4104?

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Is CVE-2021-4104 actively exploited?

Active exploitation of CVE-2021-4104 has not been confirmed. The EPSS score is 72.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-4104?

CVE-2021-4104 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-4104 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.