{"cvss":0.0,"datePublished":"2023-05-01","dateUpdated":"2023-05-01","description":"Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.","dueDate":"2023-05-22","id":"CVE-2021-45046","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046","product":"Log4j2","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Apache Log4j2 Deserialization of Untrusted Data Vulnerability","vendor":"Apache"}