Maven package intelligence

org.xbib.elasticsearch:log4j Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.xbib.elasticsearch:log4j, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.xbib.elasticsearch:log4j
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
org.xbib.elasticsearch:log4j KEV with sensor-observed exploitation activity

Review org.xbib.elasticsearch:log4j exploitation against the versions you run

All one exploited org.xbib.elasticsearch:log4j vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.xbib.elasticsearch:log4j vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

In CISA 10 Dec 2021

Recurring weakness patterns

Improper Input Validation, Uncontrolled Resource Consumption, and Deserialization of Untrusted Data account for mapped occurrences across this org.xbib.elasticsearch:log4j KEV portfolio.

Browse all KEVs →