AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2021-45046.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSCISA known exploitedAdded May 01, 2023
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

# Impact The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack. ## Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use. # Mitigation Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. This issue can be mitigated in prior releases (< 2.16.0) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). Log4j 2.15.0 restricts JNDI LDAP lookups

CISA remediation guidance

Apply updates per vendor instructions.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-7rjr-3q55-vv33

Open original source · Updated Oct 02, 2026

Incomplete fix for Apache Log4j vulnerability

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
mavenorg.apache.logging.log4j:log4j-core>= 2.13.0, < 2.16.02.16.0
mavenorg.ops4j.pax.logging:pax-logging-log4j2>= 1.8.0, < 1.9.21.9.2
mavenorg.ops4j.pax.logging:pax-logging-log4j2>= 1.10.0, < 1.10.81.10.8
mavenorg.ops4j.pax.logging:pax-logging-log4j2>= 1.11.0, < 1.11.111.11.11
mavenorg.ops4j.pax.logging:pax-logging-log4j2>= 2.0.0, < 2.0.122.0.12
mavenorg.apache.logging.log4j:log4j-core>= 2.4.0, < 2.12.22.12.2
mavenorg.apache.logging.log4j:log4j-core< 2.3.12.3.1

Original records & references

PUBLISHED 2021-12-14T13:01:28-05:00
MODIFIED 2026-10-02T16:21:54-04:00
INGESTED 2026-10-06T11:45:17-04:00