VDB

RHSA-2022%3A0236

RHSA-2022%3A0236 PUBLISHED CVSS 6.599999904632568 MEDIUM

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Risk Scores

CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatopenshift3/ose-logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64
Red Hatopenshift3/ose-logging-curator5@sha256:615464e77119620f0e248dc8702c790fc12e004393fcef65731b7ab0c8fe51ea_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-curator5@sha256:615464e77119620f0e248dc8702c790fc12e004393fcef65731b7ab0c8fe51ea_amd64
Red Hatopenshift3/logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64
Red Hatopenshift3/ose-logging-kibana5@sha256:531d1444a26b4c38316fd7e46e7d619a519e7a2d1b0a78567949160eb0196860_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5@sha256:531d1444a26b4c38316fd7e46e7d619a519e7a2d1b0a78567949160eb0196860_amd64
Red Hatopenshift3/ose-logging-elasticsearch5@sha256:730f0aea1c470224fbe8a4c3e2ad0600bb213f39b79aa5b473146bae50a28b4f_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5@sha256:730f0aea1c470224fbe8a4c3e2ad0600bb213f39b79aa5b473146bae50a28b4f_amd64
Red Hatopenshift3/ose-logging-eventrouter@sha256:cc44602e7ec89f3c145288c4e65f0d3d418454fcf4147aa7a1deafeda9329209_amd64 as a component of Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-eventrouter@sha256:cc44602e7ec89f3c145288c4e65f0d3d418454fcf4147aa7a1deafeda9329209_amd64

Timeline

  • Jan 25, 2022 CVE Published
  • Mar 19, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›