HIGH · 7.5

CVE-2021-4104

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnection...

Vulnerability Description

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheLog4J1.2
FedoraprojectFedora35
RedhatCodeready Studio12.0
RedhatIntegration Camel K-
RedhatIntegration Camel Quarkus-
RedhatJboss A-Mq6.0.0
RedhatJboss A-Mq Streaming-
RedhatJboss Data Grid7.0.0
RedhatJboss Data Virtualization6.0.0
RedhatJboss Enterprise Application Platform6.0.0
RedhatJboss Fuse6.0.0
RedhatJboss Fuse Service Works6.0
RedhatJboss Operations Network3.0
RedhatJboss Web Server3.0
RedhatOpenshift Application Runtimes-
RedhatOpenshift Container Platform4.6
RedhatProcess Automation7.0
RedhatSingle Sign-On7.0
RedhatSoftware Collections-
RedhatEnterprise Linux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-4104?

CVE-2021-4104 is a vulnerability with a CVSS score of 7.5 (HIGH). JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnection...

How severe is CVE-2021-4104?

CVE-2021-4104 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-4104?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Log4J, Fedoraproject Fedora, Redhat Codeready Studio, Redhat Integration Camel K, Redhat Integration Camel Quarkus.