VDB
RHSA-2022%3A0485
RHSA-2022%3A0485
PUBLISHED
CVSS 6.599999904632568 MEDIUM
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Risk Scores
CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-egress-http-proxy@sha256:39a831a45748dfd91a1d20f68481fbc82bd3fefa4cb5ff87aab478770582de2f_s390x as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:cef6c19c4b400e88a5231b626970ca205af002ae004f0e40c2bb5b3281abb44b_ppc64le as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-egress-http-proxy@sha256:cef6c19c4b400e88a5231b626970ca205af002ae004f0e40c2bb5b3281abb44b_ppc64le |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:bf92e1a223de2fe51d8e702f7bcd924e83378b99a249e76f1f8db7167a34e155_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-node-problem-detector-rhel8@sha256:05c5fff8726da0dbd9270314bf227eda559969e5abcbabd25078fa7e4f1e99eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-node-problem-detector-rhel8@sha256:05c5fff8726da0dbd9270314bf227eda559969e5abcbabd25078fa7e4f1e99eb_ppc64le |
| Red Hat | openshift4/ose-metering-presto@sha256:cd1d23fd5dff2a78fba377fbb3b1c63d922877af09f17e1c1f898eeaa4891c03_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-metering-presto@sha256:cd1d23fd5dff2a78fba377fbb3b1c63d922877af09f17e1c1f898eeaa4891c03_amd64 |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:7165575c0b49cf25bdafbb7390199d2a957322147fadfdce1401afc10dfcb37d_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-sriov-operator-must-gather@sha256:baa3b6da137bc048f57d656f938c71d26e8240f4a5a7d99dab584a1662d19188_s390x as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:94572c353a049edb1ebc935a73a15e78ef399b9f15f3bb9b8bf376f1b37dff87_ppc64le as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ptp-must-gather-rhel8@sha256:94572c353a049edb1ebc935a73a15e78ef399b9f15f3bb9b8bf376f1b37dff87_ppc64le |
| Red Hat | openshift4/ose-metering-helm-container-rhel8@sha256:982bc5a04515bf30e88eff06b742ee4b0720d26b2039aef229e89ea52bc4322a_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-metering-helm-container-rhel8@sha256:982bc5a04515bf30e88eff06b742ee4b0720d26b2039aef229e89ea52bc4322a_amd64 |
| Red Hat | openshift4/ose-ptp-operator@sha256:d2e84963c0a4b8c4837c600dcd45a4ec85582dcb277cc5a342772cfaf37a02d6_s390x as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:050f5694076ad7712ea486db9c3a6da60f14a6bcdefb93f09ae5a5d0d2350216_s390x as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6df1c3e3f99b59c1dcc1ba4bc50aef9638ec28eeb4a358316b6b5c5eb9ce1c1a_ppc64le as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6df1c3e3f99b59c1dcc1ba4bc50aef9638ec28eeb4a358316b6b5c5eb9ce1c1a_ppc64le |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:4210a5b83b7a6dce2e8b5e9c74b2c2858b4441c7e7046dc1bc47d13bade5b344_s390x as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-cluster-kube-descheduler-operator@sha256:4210a5b83b7a6dce2e8b5e9c74b2c2858b4441c7e7046dc1bc47d13bade5b344_s390x |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:7f191475c9dd43d6b40efd4b565bf677af22b1b654e0f5d8829b4831abc715d5_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-operator-sdk-rhel8@sha256:7f191475c9dd43d6b40efd4b565bf677af22b1b654e0f5d8829b4831abc715d5_amd64 |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:3a1ede2d5f064cdc9c3dcae93122e30fe6acb8962905ea739484840c028767eb_s390x as a component of Red Hat OpenShift Container Platform 4.8 | * |
| Red Hat | openshift4/ose-ptp-operator@sha256:bb73adc511485987f4b20db03ef164ea82c28bf1fb3cf5c50ecaa3b8bd5e268f_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-ptp-operator@sha256:bb73adc511485987f4b20db03ef164ea82c28bf1fb3cf5c50ecaa3b8bd5e268f_amd64 |
| Red Hat | openshift4/ose-node-problem-detector-rhel8@sha256:3fddde918aae7343b55fb4bdd8273d8a928030d95465cb4c699d92958761a7a1_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-node-problem-detector-rhel8@sha256:3fddde918aae7343b55fb4bdd8273d8a928030d95465cb4c699d92958761a7a1_amd64 |
| Red Hat | openshift4/ose-local-storage-static-provisioner@sha256:2365ccb37a8f91f4ce8c0681e304f98f9468ccd3e7e9cb6bfe7e7179cdad9998_s390x as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-local-storage-static-provisioner@sha256:2365ccb37a8f91f4ce8c0681e304f98f9468ccd3e7e9cb6bfe7e7179cdad9998_s390x |
| Red Hat | openshift4/ose-local-storage-static-provisioner@sha256:030c266a9d55bd63d837fae36a1550a2607e684e8ccfd78fb229b2a028d8897f_ppc64le as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-local-storage-static-provisioner@sha256:030c266a9d55bd63d837fae36a1550a2607e684e8ccfd78fb229b2a028d8897f_ppc64le |
| Red Hat | openshift4/ose-local-storage-mustgather-rhel8@sha256:7aa0f9ceaa8663081cf19d8a2c689d6356d467ce5ccfb1a6140101f5a47973b6_s390x as a component of Red Hat OpenShift Container Platform 4.8 | openshift4/ose-local-storage-mustgather-rhel8@sha256:7aa0f9ceaa8663081cf19d8a2c689d6356d467ce5ccfb1a6140101f5a47973b6_s390x |
…and 94 more
Timeline
- Feb 16, 2022 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:0485 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2035951 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0485.json advisory
- https://access.redhat.com/security/cve/CVE-2021-44832 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-44832 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44832 advisory
- https://issues.apache.org/jira/browse/LOG4J2-3293 advisory