VDB
RHSA-2021%3A5206
RHSA-2021%3A5206
PUBLISHED
CVSS 7.5 HIGH
Red Hat Security Advisory: log4j security update
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:rhel_els:6 | log4j | 0, 0 |
| Red Hat:enterprise_linux:7::server | log4j | 0, 0 |
| Red Hat:enterprise_linux:7::computenode | log4j-javadoc | 0, 0 |
| Red Hat:rhel_aus:7.6::server | log4j | 0, 0 |
| Red Hat:rhel_tus:7.6::server | log4j-manual | 0, 0 |
| Red Hat:rhel_aus:7.7::server | log4j-javadoc | 0, 0 |
| Red Hat:enterprise_linux:7::client | log4j-manual | 0, 0 |
| Red Hat:rhel_els:6 | log4j-debuginfo | 0, 0 |
| Red Hat:rhel_e4s:7.6::server | log4j | 0, 0 |
| Red Hat:enterprise_linux:7::client | log4j | 0, 0 |
| Red Hat:enterprise_linux:7::workstation | log4j-manual | 0, 0 |
| Red Hat:enterprise_linux:7::client | log4j-javadoc | 0, 0 |
| Red Hat:rhel_tus:7.7::server | log4j-manual | 0, 0 |
| Red Hat:enterprise_linux:7::workstation | log4j | 0, 0 |
| Red Hat:rhel_aus:7.6::server | log4j-manual | 0, 0 |
| Red Hat:rhel_aus:7.3::server | log4j-manual | 0, 0 |
| Red Hat:rhel_tus:7.6::server | log4j | 0, 0 |
| Red Hat:rhel_e4s:7.7::server | log4j-manual | 0, 0 |
| Red Hat:enterprise_linux:7::server | log4j-javadoc | 0, 0 |
| Red Hat:rhel_els:6 | log4j-javadoc | 0, 0 |
…and 20 more
Timeline
- Dec 20, 2021 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:5206 advisory
- https://access.redhat.com/security/updates/classification/#moderate article
- https://access.redhat.com/security/vulnerabilities/RHSB-2021-009 article
- https://bugzilla.redhat.com/show_bug.cgi?id=2031667 report
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_5206.json advisory
- https://access.redhat.com/security/cve/CVE-2021-4104 report
- https://www.cve.org/CVERecord?id=CVE-2021-4104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-4104 advisory
- https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126 article
- https://github.com/apache/logging-log4j2/pull/608#issuecomment-991723301 article
- https://lists.apache.org/thread/0x4zvtq92yggdgvwfgsftqrj4xx5w0nx article
- https://www.openwall.com/lists/oss-security/2021/12/13/1 article