CVE-2021-45046: Log4j Incomplete Fix (Log4Shell Follow-up)
A follow-up vulnerability in Apache Log4j2 showing that the initial Log4Shell (CVE-2021-44228) fix in version 2.15.0 was incomplete. In non-default configurations using a Context Lookup in the logging pattern, attacker-controlled input could still craft a malicious lookup string that survived 2.15.0's sanitization, causing denial of service and, in some configurations, remote code execution. NVD initially scored this a low-severity DoS issue, then revised it upward once further analysis confirmed RCE was reachable in more setups than first believed.
View the authoritative record on NVD ↗Affected software
- Apache Log4j2 2.0-beta9 through 2.15.0 (excluding the backported-fix 2.12.2 release)
How it's exploited
In an application that logs a value through a Context Lookup pattern (such as $${ctx:loginId}), submit input containing a crafted lookup string that evades 2.15.0's incomplete Thread Context Map sanitization, resulting in denial of service or, in configurations using a non-default Pattern Layout, remote code execution.
Severity
CVE-2021-45046 carries a CVSS 3.1 base score of 9.0, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-45046 is categorized under CWE-917, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to Log4j2 2.17.1 or later; do not stop at 2.16.0 or 2.15.0, both of which were superseded by fixes for this and subsequent related issues (CVE-2021-45105, CVE-2021-44832).
Frequently asked questions
What is CVE-2021-45046?
A follow-up vulnerability in Apache Log4j2 showing that the initial Log4Shell (CVE-2021-44228) fix in version 2.15.0 was incomplete. In non-default configurations using a Context Lookup in the logging pattern, attacker-controlled input could still craft a malicious lookup string that survived 2.15.0's sanitization, causing denial of service and, in some configurations, remote code execution. NVD initially scored this a low-severity DoS issue, then revised it upward once further analysis confirmed RCE was reachable in more setups than first believed.
How severe is CVE-2021-45046?
CVE-2021-45046 has a CVSS 3.1 base score of 9.0 out of 10, rated Critical.
What software is affected by CVE-2021-45046?
CVE-2021-45046 affects Apache Log4j2 2.0-beta9 through 2.15.0 (excluding the backported-fix 2.12.2 release).
How do you fix CVE-2021-45046?
Upgrade to Log4j2 2.17.1 or later; do not stop at 2.16.0 or 2.15.0, both of which were superseded by fixes for this and subsequent related issues (CVE-2021-45105, CVE-2021-44832).
Where is the authoritative record for CVE-2021-45046?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-45046 at https://nvd.nist.gov/vuln/detail/CVE-2021-45046, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest