#VU59098 Code Injection in Apache Log4j - CVE-2021-44832
Published: December 28, 2021 / Updated: April 25, 2022
Apache Log4j
Apache Foundation
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code.