Skip to content

Remote code injection in Log4j (through pax-logging-log4j2)

Critical
grgrzybek published GHSA-xxfh-x98p-j8fr Dec 10, 2021

Package

maven pax-logging-log4j2 (Maven)

Affected versions

< 2.0.11
< 1.11.10

Patched versions

2.0.11
1.11.10

Description

Impact

Remote Code Execution.

Patches

Users of pax-logging 1.11.9 should update to 1.11.10.
Users of pax-logging 2.0.10 should update to 2.0.11.

Workarounds

Set system property -Dlog4j2.formatMsgNoLookups=true

References

GHSA-jfh8-c2jp-5v3q

Severity

Critical

CVE ID

CVE-2021-44228

Weaknesses

No CWEs