Maven package intelligence

org.apache.logging.log4j:log4j-core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.logging.log4j:log4j-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting org.apache.logging.log4j:log4j-core
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
org.apache.logging.log4j:log4j-core KEV with sensor-observed exploitation activity

Review org.apache.logging.log4j:log4j-core exploitation against the versions you run

All two exploited org.apache.logging.log4j:log4j-core vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.apache.logging.log4j:log4j-core vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

In CISA 10 Dec 2021
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

In CISA 01 May 2023

Recurring weakness patterns

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection'), Improper Input Validation, and Uncontrolled Resource Consumption account for mapped occurrences across this org.apache.logging.log4j:log4j-core KEV portfolio.

Browse all KEVs →