BSA-2021-1655
21310
21 December 2021
21 December 2021
Closed
Medium
5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
No
CVE-2021-45105
Summary Security Advisory ID : BSA-2021-1655 Component : Apache Log4j StrSubstitutor Revision : 1.0
Apache Log4j2 versions 2.0-alpha1 through 2.16.0, excluding 2.12.3, did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DOS (Denial of Service) attack.
More information is available at the links below.Apache : https://logging.apache.org/log4j/2.x/security.html
ZDI: https://www.zerodayinitiative.com/blog/2021/12/17/cve-2021-45105-denial-of-service-via-uncontrolled-recursion-in-log4j-strsubstitutor
Brocade has investigated its product line to determine the exposure of Brocade Fibre Channel products from Broadcom.
Products Confirmed Not Vulnerable
No Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Revision History
| Version | Change | Date |
|---|---|---|
| 1.0 | Initial Publication | December 21, 2021 |