VDB

RHSA-2022%3A0485

RHSA-2022%3A0485 PUBLISHED CVSS 6.599999904632568 MEDIUM

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Risk Scores

CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-egress-http-proxy@sha256:39a831a45748dfd91a1d20f68481fbc82bd3fefa4cb5ff87aab478770582de2f_s390x as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-egress-http-proxy@sha256:cef6c19c4b400e88a5231b626970ca205af002ae004f0e40c2bb5b3281abb44b_ppc64le as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-egress-http-proxy@sha256:cef6c19c4b400e88a5231b626970ca205af002ae004f0e40c2bb5b3281abb44b_ppc64le
Red Hatopenshift4/kubernetes-nmstate-rhel8-operator@sha256:bf92e1a223de2fe51d8e702f7bcd924e83378b99a249e76f1f8db7167a34e155_amd64 as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-node-problem-detector-rhel8@sha256:05c5fff8726da0dbd9270314bf227eda559969e5abcbabd25078fa7e4f1e99eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-node-problem-detector-rhel8@sha256:05c5fff8726da0dbd9270314bf227eda559969e5abcbabd25078fa7e4f1e99eb_ppc64le
Red Hatopenshift4/ose-metering-presto@sha256:cd1d23fd5dff2a78fba377fbb3b1c63d922877af09f17e1c1f898eeaa4891c03_amd64 as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-metering-presto@sha256:cd1d23fd5dff2a78fba377fbb3b1c63d922877af09f17e1c1f898eeaa4891c03_amd64
Red Hatopenshift4/ose-sriov-network-device-plugin@sha256:7165575c0b49cf25bdafbb7390199d2a957322147fadfdce1401afc10dfcb37d_amd64 as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:baa3b6da137bc048f57d656f938c71d26e8240f4a5a7d99dab584a1662d19188_s390x as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ptp-must-gather-rhel8@sha256:94572c353a049edb1ebc935a73a15e78ef399b9f15f3bb9b8bf376f1b37dff87_ppc64le as a component of Red Hat OpenShift Container Platform 4.8openshift4/ptp-must-gather-rhel8@sha256:94572c353a049edb1ebc935a73a15e78ef399b9f15f3bb9b8bf376f1b37dff87_ppc64le
Red Hatopenshift4/ose-metering-helm-container-rhel8@sha256:982bc5a04515bf30e88eff06b742ee4b0720d26b2039aef229e89ea52bc4322a_amd64 as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-metering-helm-container-rhel8@sha256:982bc5a04515bf30e88eff06b742ee4b0720d26b2039aef229e89ea52bc4322a_amd64
Red Hatopenshift4/ose-ptp-operator@sha256:d2e84963c0a4b8c4837c600dcd45a4ec85582dcb277cc5a342772cfaf37a02d6_s390x as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-cluster-nfd-operator@sha256:050f5694076ad7712ea486db9c3a6da60f14a6bcdefb93f09ae5a5d0d2350216_s390x as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6df1c3e3f99b59c1dcc1ba4bc50aef9638ec28eeb4a358316b6b5c5eb9ce1c1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6df1c3e3f99b59c1dcc1ba4bc50aef9638ec28eeb4a358316b6b5c5eb9ce1c1a_ppc64le
Red Hatopenshift4/ose-cluster-kube-descheduler-operator@sha256:4210a5b83b7a6dce2e8b5e9c74b2c2858b4441c7e7046dc1bc47d13bade5b344_s390x as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-cluster-kube-descheduler-operator@sha256:4210a5b83b7a6dce2e8b5e9c74b2c2858b4441c7e7046dc1bc47d13bade5b344_s390x
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:7f191475c9dd43d6b40efd4b565bf677af22b1b654e0f5d8829b4831abc715d5_amd64 as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-operator-sdk-rhel8@sha256:7f191475c9dd43d6b40efd4b565bf677af22b1b654e0f5d8829b4831abc715d5_amd64
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:3a1ede2d5f064cdc9c3dcae93122e30fe6acb8962905ea739484840c028767eb_s390x as a component of Red Hat OpenShift Container Platform 4.8*
Red Hatopenshift4/ose-ptp-operator@sha256:bb73adc511485987f4b20db03ef164ea82c28bf1fb3cf5c50ecaa3b8bd5e268f_amd64 as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-ptp-operator@sha256:bb73adc511485987f4b20db03ef164ea82c28bf1fb3cf5c50ecaa3b8bd5e268f_amd64
Red Hatopenshift4/ose-node-problem-detector-rhel8@sha256:3fddde918aae7343b55fb4bdd8273d8a928030d95465cb4c699d92958761a7a1_amd64 as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-node-problem-detector-rhel8@sha256:3fddde918aae7343b55fb4bdd8273d8a928030d95465cb4c699d92958761a7a1_amd64
Red Hatopenshift4/ose-local-storage-static-provisioner@sha256:2365ccb37a8f91f4ce8c0681e304f98f9468ccd3e7e9cb6bfe7e7179cdad9998_s390x as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-local-storage-static-provisioner@sha256:2365ccb37a8f91f4ce8c0681e304f98f9468ccd3e7e9cb6bfe7e7179cdad9998_s390x
Red Hatopenshift4/ose-local-storage-static-provisioner@sha256:030c266a9d55bd63d837fae36a1550a2607e684e8ccfd78fb229b2a028d8897f_ppc64le as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-local-storage-static-provisioner@sha256:030c266a9d55bd63d837fae36a1550a2607e684e8ccfd78fb229b2a028d8897f_ppc64le
Red Hatopenshift4/ose-local-storage-mustgather-rhel8@sha256:7aa0f9ceaa8663081cf19d8a2c689d6356d467ce5ccfb1a6140101f5a47973b6_s390x as a component of Red Hat OpenShift Container Platform 4.8openshift4/ose-local-storage-mustgather-rhel8@sha256:7aa0f9ceaa8663081cf19d8a2c689d6356d467ce5ccfb1a6140101f5a47973b6_s390x

…and 94 more

Timeline

  • Feb 16, 2022 CVE Published
  • Mar 19, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›