Maven package intelligence

org.ops4j.pax.logging:pax-logging-log4j2 Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.ops4j.pax.logging:pax-logging-log4j2, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting org.ops4j.pax.logging:pax-logging-log4j2
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
org.ops4j.pax.logging:pax-logging-log4j2 KEV with sensor-observed exploitation activity

Review org.ops4j.pax.logging:pax-logging-log4j2 exploitation against the versions you run

All two exploited org.ops4j.pax.logging:pax-logging-log4j2 vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.ops4j.pax.logging:pax-logging-log4j2 vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

In CISA 10 Dec 2021
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

In CISA 01 May 2023

Recurring weakness patterns

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection'), Improper Input Validation, and Uncontrolled Resource Consumption account for mapped occurrences across this org.ops4j.pax.logging:pax-logging-log4j2 KEV portfolio.

Browse all KEVs →