VDB

RHSA-2022%3A0493

RHSA-2022%3A0493 PUBLISHED CVSS 6.599999904632568 MEDIUM

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

Risk Scores

CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-sriov-cni@sha256:82e46f02c6f0c88139dc1e20a1b61510d3ee2d42ed65118669def44a83735595_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-cni@sha256:82e46f02c6f0c88139dc1e20a1b61510d3ee2d42ed65118669def44a83735595_amd64
Red Hatopenshift4/ose-metering-helm-container-rhel8@sha256:8ef0d8b296fd6cf92b335759b0ae69e2d27b0febcfd7b8039a2a285d6872af24_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-metering-helm-container-rhel8@sha256:8ef0d8b296fd6cf92b335759b0ae69e2d27b0febcfd7b8039a2a285d6872af24_ppc64le
Red Hatopenshift4/ose-sriov-network-webhook@sha256:e8766c5b017e1d13b5da871db07511834fefa46e5fafe3d98ad128d5d9adbdaa_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-webhook@sha256:e8766c5b017e1d13b5da871db07511834fefa46e5fafe3d98ad128d5d9adbdaa_ppc64le
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:048df6fb0114e1337a8187779b9cb02de9f0afefe150a9606f33e50dcdf450f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-operator-sdk-rhel8@sha256:048df6fb0114e1337a8187779b9cb02de9f0afefe150a9606f33e50dcdf450f0_ppc64le
Red Hatopenshift4/ose-sriov-infiniband-cni@sha256:25b8e51cedf57a5cd5d84685711e4f46c06b9d3f521bac76b00fbe2fc35310b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-infiniband-cni@sha256:25b8e51cedf57a5cd5d84685711e4f46c06b9d3f521bac76b00fbe2fc35310b9_ppc64le
Red Hatopenshift4/ose-clusterresourceoverride-rhel8@sha256:b297025d05f3b5898e97bcd4c79151338605848a32028e4bf2a8e20d46a9a0e6_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-clusterresourceoverride-rhel8@sha256:b297025d05f3b5898e97bcd4c79151338605848a32028e4bf2a8e20d46a9a0e6_s390x
Red Hatopenshift4/ose-sriov-network-operator@sha256:74535f528ddf08eace2d38a42cdbdc2cc34f2e918b1ea1137aba44150404f034_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-operator@sha256:74535f528ddf08eace2d38a42cdbdc2cc34f2e918b1ea1137aba44150404f034_ppc64le
Red Hatopenshift4/ose-node-problem-detector-rhel8@sha256:9819ce4cec57a67c73ef7c806328079eeb697657d22b0205de48f887883d4263_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-node-problem-detector-rhel8@sha256:9819ce4cec57a67c73ef7c806328079eeb697657d22b0205de48f887883d4263_s390x
Red Hatopenshift4/ptp-must-gather-rhel8@sha256:a513ce618ce42f1cd4b3b3eb4d075cc229f6b2f829c355be8de29c1910d6138d_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ptp-must-gather-rhel8@sha256:a513ce618ce42f1cd4b3b3eb4d075cc229f6b2f829c355be8de29c1910d6138d_amd64
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:a270a26fe3257c4ab4020975e8ceb88ed223457497fd7bc11849ce96a0075c1c_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-operator-must-gather@sha256:a270a26fe3257c4ab4020975e8ceb88ed223457497fd7bc11849ce96a0075c1c_s390x
Red Hatopenshift4/ose-local-storage-diskmaker@sha256:14f5cc593403a32b0d3aea18b4c916b92d73bd29a784de330f2055fc549144a8_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-local-storage-diskmaker@sha256:14f5cc593403a32b0d3aea18b4c916b92d73bd29a784de330f2055fc549144a8_amd64
Red Hatopenshift4/ose-sriov-network-device-plugin@sha256:31a390e00f9a2f992508f586e6fce8c0ce046760b553ea007feee1d80c221dee_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-device-plugin@sha256:31a390e00f9a2f992508f586e6fce8c0ce046760b553ea007feee1d80c221dee_amd64
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:7cda510767be34b8ac3b808aace4ab2d61107042daa98f620993a667852b9a1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:7cda510767be34b8ac3b808aace4ab2d61107042daa98f620993a667852b9a1c_ppc64le
Red Hatopenshift4/ose-egress-router@sha256:9741b74b0deb3ef44186a0d98a58db45995b2bd404db445621d27d74c02e971f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-egress-router@sha256:9741b74b0deb3ef44186a0d98a58db45995b2bd404db445621d27d74c02e971f_ppc64le
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8@sha256:5d67547980eca90abba55217671e141a5211b188fde220a7738d00c492719a90_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:5d67547980eca90abba55217671e141a5211b188fde220a7738d00c492719a90_s390x
Red Hatopenshift4/ose-local-storage-operator@sha256:1de35e9908b4037e251d5940d6d7832add15438babbd787a8799b97d077bdb51_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-local-storage-operator@sha256:1de35e9908b4037e251d5940d6d7832add15438babbd787a8799b97d077bdb51_s390x
Red Hatopenshift4/ose-sriov-network-operator@sha256:a601452298527b60417ce4bc1cd70578fe3e6c08e5b7206a44135e87dae22fee_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-operator@sha256:a601452298527b60417ce4bc1cd70578fe3e6c08e5b7206a44135e87dae22fee_amd64
Red Hatopenshift4/ose-sriov-network-config-daemon@sha256:282eb59274ebf8c9b1d4df18957fe016a1276851504febfa7d0a82b3ff123b46_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-config-daemon@sha256:282eb59274ebf8c9b1d4df18957fe016a1276851504febfa7d0a82b3ff123b46_ppc64le
Red Hatopenshift4/ose-node-feature-discovery@sha256:b60199d0dbf4727ac8ae61fec173120db88b061ea102f9f814b77da3fdf0cb8d_s390x as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-egress-router@sha256:342350d595c18a630c6f6bb100e8e2eaa397008d3467757431e81a54cab0fe87_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-egress-router@sha256:342350d595c18a630c6f6bb100e8e2eaa397008d3467757431e81a54cab0fe87_s390x

…and 100 more

Timeline

  • Feb 16, 2022 CVE Published
  • Mar 19, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›