Known vulnerabilities in apache-log4j2 (Debian package) 2.15.0-1~deb10u1
Vendor:
Debian
Software:
apache-log4j2 (Debian package)
Version:
2.15.0-1~deb10u1
Software CPE:
cpe:2.3:o:debian:apache-log4j2_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
3
Public exploits:
2
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-45105 |
CWE-835 | Medium | 2.17.0-1~deb10u1, 2.17.0-1~deb11u1 | 18.12.2021 |
SB2021121802 SB2021121903 SB2021122011 and 169 more |
||
| #VU58976 - Improper Control of Generation of Code ('Code Injection') CVE-2021-45046 |
CWE-94 | High | 2.16.0-1~deb10u1, 2.16.0-1~deb11u1 | 15.12.2021 |
SB2021121504 SB2021121511 SB2021121512 and 178 more |
||
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | 2.16.0-1~deb10u1, 2.16.0-1~deb11u1 | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |