You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to dependency file: /sonatype-depshield-demo/pom.xml
Path to vulnerable library: /2/repository/org/apache/logging/log4j/log4j-core/2.8.1/log4j-core-2.8.1.jar
Dependency Hierarchy:
❌ log4j-core-2.8.1.jar (Vulnerable Library)
Vulnerability Details
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
mend-bolt-for-githubbot
changed the title
CVE-2021-45105 (High) detected in log4j-core-2.8.1.jar
CVE-2021-45105 (Medium) detected in log4j-core-2.8.1.jar
Mar 4, 2022
CVE-2021-45105 - Medium Severity Vulnerability
Vulnerable Library - log4j-core-2.8.1.jar
The Apache Log4j Implementation
Library home page: https://logging.apache.org/log4j/2.x/
Path to dependency file: /sonatype-depshield-demo/pom.xml
Path to vulnerable library: /2/repository/org/apache/logging/log4j/log4j-core/2.8.1/log4j-core-2.8.1.jar
Dependency Hierarchy:
Vulnerability Details
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Publish Date: 2021-12-18
URL: CVE-2021-45105
CVSS 3 Score Details (5.9)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://logging.apache.org/log4j/2.x/security.html
Release Date: 2021-12-18
Fix Resolution: 2.12.3
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: