CVE-2021-44228 -- liblog4j2-javaID: oval:org.secpod.oval:def:76362 | Date: (C)2021-12-10 (M)2023-12-14 |
Class: VULNERABILITY | Family: unix |
A flaw was found in the Java logging library Apache Log4j 2 in versions from 2.0.0 and before and including 2.14.1 which could allow a remote attacker to execute code on the server if the system logs an attacker controlled string value with the attacker's JNDI LDAP server lookup. The highest threat from the vulnerability is to data confidentiality and integrity as well as system availability.
Platform: |
Debian 11.x |
Debian 10.x |
Debian 9.x |