GHSA-7rjr-3q55-vv33
CRITICALCVE-2021-45046The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern
- Affected
- >= 2.13.0, < 2.16.0
- Fixed in
- 2.16.0
- Weakness
- CWE-502
- Published
- 2021-12-14
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference