FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

graylog -- include log4j patches

Affected packages
graylog < 4.2.3

Details

VuXML ID 3fadd7e4-f8fb-45a0-a218-8fd6423c338f
Discovery 2021-12-10
Entry 2021-12-11

Apache Software Foundation repos:

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or paramters can execute arbitrary code from attacker-controller LDAP servers when message lookup substitution is enabled.

References

CVE Name CVE-2021-44228
URL https://github.com/Graylog2/graylog2-server/commit/d3e441f1126f0dc292e986879039a87c59375b2a
URL https://logging.apache.org/log4j/2.x/security.html