CVE-2021-45046: Second Log4j Security Vulnerability Discovered
ID: 176002c1-db06-556f-ab49-e7daa84c389d
STIX ID: report--176002c1-db06-556f-ab49-e7daa84c389d
Feed Name: Aqua Security Blog
The report describes a recently discovered Log4j vulnerability (CVE-2021-45046) caused by an incomplete fix in Log4j 2.15.0 that can enable denial-of-service and, in certain scenarios, remote code execution; it notes the CVSSv3 score was raised to 9.0, recommends upgrading to Log4j 2.16.0 (which disables JNDI by default), warns that prior mitigations like formatMsgNoLookups may be insufficient, and advises using detection tools such as Aqua's Trivy to find and remediate affected software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
