- 漏洞ID:
- 漏洞类型:其他
- 发布日期:2021-12-18
- 更新时间:2021-12-20
- CVE编号:CVE-2021-45105
- CNNVD-ID:CNNVD-202112-1493
- 漏洞平台:
- CVSS评分:
Guy Lederfein of T...
Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。
Apache Log4j2 2.0-alpha1到2.16.0版本(不包括2.12.3)存在安全漏洞,该漏洞源于自引用查找的不受控递归。攻击者可利用该漏洞在解释精心编制的字符串时导致拒绝服务。此问题已在2.17.0 和 2.12.3中修复。
来源:MISC
链接:https://logging.apache.org/log4j/2.x/security.html
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20211218-0001/
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/12/19/1
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-5024
来源:MISC
链接:https://www.zerodayinitiative.com/advisories/ZDI-21-1541/
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.4313
来源:www.zerodayinitiative.com
链接:https://www.zerodayinitiative.com/advisories/ZDI-21-1541/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021121903