Teisoft Exposure Platform
Sign in
criticalCVE-2021-44228CVSS 10

Apache Log4j2 Remote Code Injection

Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.

Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.

No signup. Takes about a minute. We request pages your server already serves publicly — nothing is written, exploited or brute-forced.

How to fix it

Upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later).

What this check actually does

  • Fingerprints the host — server, technologies, certificate and response headers.
  • Runs the Apache Log4j2 Remote Code Injection detection against it.
  • Runs a short pass for common misconfigurations, exposed files and TLS problems.
  • Cross-references the detected versions against published CVEs.

Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.

Tags

cve2021cverceoastlog4jinjectionkevapachevkevvuln