VDB
RHSA-2022%3A0236
RHSA-2022%3A0236
PUBLISHED
CVSS 6.599999904632568 MEDIUM
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Risk Scores
CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift3/ose-logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 |
| Red Hat | openshift3/ose-logging-curator5@sha256:615464e77119620f0e248dc8702c790fc12e004393fcef65731b7ab0c8fe51ea_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-curator5@sha256:615464e77119620f0e248dc8702c790fc12e004393fcef65731b7ab0c8fe51ea_amd64 |
| Red Hat | openshift3/logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/logging-fluentd@sha256:d8de79c838c86c85fba55880ff3b59cfb8c6f89b0e092d65e13833d10a949012_amd64 |
| Red Hat | openshift3/ose-logging-kibana5@sha256:531d1444a26b4c38316fd7e46e7d619a519e7a2d1b0a78567949160eb0196860_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-kibana5@sha256:531d1444a26b4c38316fd7e46e7d619a519e7a2d1b0a78567949160eb0196860_amd64 |
| Red Hat | openshift3/ose-logging-elasticsearch5@sha256:730f0aea1c470224fbe8a4c3e2ad0600bb213f39b79aa5b473146bae50a28b4f_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-elasticsearch5@sha256:730f0aea1c470224fbe8a4c3e2ad0600bb213f39b79aa5b473146bae50a28b4f_amd64 |
| Red Hat | openshift3/ose-logging-eventrouter@sha256:cc44602e7ec89f3c145288c4e65f0d3d418454fcf4147aa7a1deafeda9329209_amd64 as a component of Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-eventrouter@sha256:cc44602e7ec89f3c145288c4e65f0d3d418454fcf4147aa7a1deafeda9329209_amd64 |
Timeline
- Jan 25, 2022 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:0236 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2035951 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0236.json advisory
- https://access.redhat.com/security/cve/CVE-2021-44832 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-44832 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44832 advisory
- https://issues.apache.org/jira/browse/LOG4J2-3293 advisory