VDB
RHSA-2022%3A0493
RHSA-2022%3A0493
PUBLISHED
CVSS 6.599999904632568 MEDIUM
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Risk Scores
CVSS 3.1
6.599999904632568
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-sriov-cni@sha256:82e46f02c6f0c88139dc1e20a1b61510d3ee2d42ed65118669def44a83735595_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-cni@sha256:82e46f02c6f0c88139dc1e20a1b61510d3ee2d42ed65118669def44a83735595_amd64 |
| Red Hat | openshift4/ose-metering-helm-container-rhel8@sha256:8ef0d8b296fd6cf92b335759b0ae69e2d27b0febcfd7b8039a2a285d6872af24_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-metering-helm-container-rhel8@sha256:8ef0d8b296fd6cf92b335759b0ae69e2d27b0febcfd7b8039a2a285d6872af24_ppc64le |
| Red Hat | openshift4/ose-sriov-network-webhook@sha256:e8766c5b017e1d13b5da871db07511834fefa46e5fafe3d98ad128d5d9adbdaa_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-webhook@sha256:e8766c5b017e1d13b5da871db07511834fefa46e5fafe3d98ad128d5d9adbdaa_ppc64le |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:048df6fb0114e1337a8187779b9cb02de9f0afefe150a9606f33e50dcdf450f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-operator-sdk-rhel8@sha256:048df6fb0114e1337a8187779b9cb02de9f0afefe150a9606f33e50dcdf450f0_ppc64le |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:25b8e51cedf57a5cd5d84685711e4f46c06b9d3f521bac76b00fbe2fc35310b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-infiniband-cni@sha256:25b8e51cedf57a5cd5d84685711e4f46c06b9d3f521bac76b00fbe2fc35310b9_ppc64le |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8@sha256:b297025d05f3b5898e97bcd4c79151338605848a32028e4bf2a8e20d46a9a0e6_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-clusterresourceoverride-rhel8@sha256:b297025d05f3b5898e97bcd4c79151338605848a32028e4bf2a8e20d46a9a0e6_s390x |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:74535f528ddf08eace2d38a42cdbdc2cc34f2e918b1ea1137aba44150404f034_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:74535f528ddf08eace2d38a42cdbdc2cc34f2e918b1ea1137aba44150404f034_ppc64le |
| Red Hat | openshift4/ose-node-problem-detector-rhel8@sha256:9819ce4cec57a67c73ef7c806328079eeb697657d22b0205de48f887883d4263_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-node-problem-detector-rhel8@sha256:9819ce4cec57a67c73ef7c806328079eeb697657d22b0205de48f887883d4263_s390x |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:a513ce618ce42f1cd4b3b3eb4d075cc229f6b2f829c355be8de29c1910d6138d_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ptp-must-gather-rhel8@sha256:a513ce618ce42f1cd4b3b3eb4d075cc229f6b2f829c355be8de29c1910d6138d_amd64 |
| Red Hat | openshift4/ose-sriov-operator-must-gather@sha256:a270a26fe3257c4ab4020975e8ceb88ed223457497fd7bc11849ce96a0075c1c_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-operator-must-gather@sha256:a270a26fe3257c4ab4020975e8ceb88ed223457497fd7bc11849ce96a0075c1c_s390x |
| Red Hat | openshift4/ose-local-storage-diskmaker@sha256:14f5cc593403a32b0d3aea18b4c916b92d73bd29a784de330f2055fc549144a8_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-local-storage-diskmaker@sha256:14f5cc593403a32b0d3aea18b4c916b92d73bd29a784de330f2055fc549144a8_amd64 |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:31a390e00f9a2f992508f586e6fce8c0ce046760b553ea007feee1d80c221dee_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-device-plugin@sha256:31a390e00f9a2f992508f586e6fce8c0ce046760b553ea007feee1d80c221dee_amd64 |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:7cda510767be34b8ac3b808aace4ab2d61107042daa98f620993a667852b9a1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:7cda510767be34b8ac3b808aace4ab2d61107042daa98f620993a667852b9a1c_ppc64le |
| Red Hat | openshift4/ose-egress-router@sha256:9741b74b0deb3ef44186a0d98a58db45995b2bd404db445621d27d74c02e971f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-egress-router@sha256:9741b74b0deb3ef44186a0d98a58db45995b2bd404db445621d27d74c02e971f_ppc64le |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:5d67547980eca90abba55217671e141a5211b188fde220a7738d00c492719a90_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:5d67547980eca90abba55217671e141a5211b188fde220a7738d00c492719a90_s390x |
| Red Hat | openshift4/ose-local-storage-operator@sha256:1de35e9908b4037e251d5940d6d7832add15438babbd787a8799b97d077bdb51_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-local-storage-operator@sha256:1de35e9908b4037e251d5940d6d7832add15438babbd787a8799b97d077bdb51_s390x |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:a601452298527b60417ce4bc1cd70578fe3e6c08e5b7206a44135e87dae22fee_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:a601452298527b60417ce4bc1cd70578fe3e6c08e5b7206a44135e87dae22fee_amd64 |
| Red Hat | openshift4/ose-sriov-network-config-daemon@sha256:282eb59274ebf8c9b1d4df18957fe016a1276851504febfa7d0a82b3ff123b46_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-config-daemon@sha256:282eb59274ebf8c9b1d4df18957fe016a1276851504febfa7d0a82b3ff123b46_ppc64le |
| Red Hat | openshift4/ose-node-feature-discovery@sha256:b60199d0dbf4727ac8ae61fec173120db88b061ea102f9f814b77da3fdf0cb8d_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-egress-router@sha256:342350d595c18a630c6f6bb100e8e2eaa397008d3467757431e81a54cab0fe87_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-egress-router@sha256:342350d595c18a630c6f6bb100e8e2eaa397008d3467757431e81a54cab0fe87_s390x |
…and 100 more
Timeline
- Feb 16, 2022 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:0493 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2035951 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0493.json advisory
- https://access.redhat.com/security/cve/CVE-2021-44832 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-44832 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44832 advisory
- https://issues.apache.org/jira/browse/LOG4J2-3293 advisory