Categories: US-Cert-Repository

Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation



Original release date: December 10, 2021

The Apache Software Foundation has released a security advisory to address a remote code execution vulnerability (CVE-2021-44228) affecting Log4j versions 2.0-beta9 to 2.14.1. A remote attacker could exploit this vulnerability to take control of an affected system. Log4j is an open-source, Java-based logging utility widely used by enterprise applications and cloud services.

CISA encourages users and administrators to review the Apache Log4j 2.15.0 Announcement and upgrade to Log4j 2.15.0 or apply the recommended mitigations immediately.
 

This product is provided subject to this Notification and this Privacy & Use policy.



Source link

admin

Share
Published by
admin

Recent Posts

Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express

Systems Affected   Microsoft Windows Systems   Overview   Microsoft has released a Security Bulletin…

11 hours ago

Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express

Systems Affected   Microsoft Windows Systems   Overview   Microsoft has released a Security Bulletin…

1 day ago

New Variant of MyDoom Virus

Systems Affected   Microsoft Windows Systems   Overview   A new variant of the MyDoom…

2 days ago

Multiple Vulnerabilities in Systems Running Microsoft Windows

Systems Affected   Microsoft Windows systems; specifically, some versions of the following programs: Microsoft Windows…

3 days ago

Critical Vulnerabilities in Microsoft Windows

Systems Affected These vulnerabilities affect the following versions of Microsoft Internet Explorer: Microsoft Internet Explorer…

4 days ago

Multiple Vulnerabilities in libpng

Systems Affected Applications and systems that use the libpng library. Overview Several vulnerabilities exist in…

5 days ago

This website uses cookies.