logo

CVE-2021-45046: Second Log4j Security Vulnerability Discovered

ID: 176002c1-db06-556f-ab49-e7daa84c389d

STIX ID: report--176002c1-db06-556f-ab49-e7daa84c389d

Feed Name: Aqua Security Blog

Threat Score
85/100

Date Published: 2021-12-15

Date Updated: 2026-04-26

...
...

The report describes a recently discovered Log4j vulnerability (CVE-2021-45046) caused by an incomplete fix in Log4j 2.15.0 that can enable denial-of-service and, in certain scenarios, remote code execution; it notes the CVSSv3 score was raised to 9.0, recommends upgrading to Log4j 2.16.0 (which disables JNDI by default), warns that prior mitigations like formatMsgNoLookups may be insufficient, and advises using detection tools such as Aqua's Trivy to find and remediate affected software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.