CVE-2021-45105

Source
https://cve.org/CVERecord?id=CVE-2021-45105
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-45105.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-45105
Aliases
Downstream
Related
Published
2021-12-18T12:15:07.433Z
Modified
2026-02-24T11:42:26.171473Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

References

Affected packages

Git
github.com/aaugustin/websockets

Affected ranges

Type
GIT
Repo
https://github.com/aaugustin/websockets
Events

Affected versions

2.*
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-45105.json"
github.com/jetty/jetty.project

Affected ranges

Type
GIT
Repo
https://github.com/jetty/jetty.project
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
PRE-MERGE-20120719-1138
jetty-7.*
jetty-7.4.4.v20110707
jetty-7.5.0.RC0
jetty-7.5.0.RC1
jetty-7.5.0.RC2
jetty-7.5.0.v20110901
jetty-7.5.1.v20110907
jetty-7.5.1.v20110908
jetty-7.5.2.v20111006
jetty-7.5.3.v20111011
jetty-7.5.4.v20111024
jetty-7.6.0.RC0
jetty-7.6.0.RC1
jetty-7.6.0.RC2
jetty-7.6.0.RC3
jetty-7.6.0.RC4
jetty-7.6.0.RC5
jetty-7.6.0.v20120125
jetty-7.6.0.v20120127
jetty-7.6.1.v20120215
jetty-7.6.10.v20130312
jetty-7.6.11.v20130520
jetty-7.6.11.v20130725
jetty-7.6.12.v20130726
jetty-7.6.13.v20130910
jetty-7.6.2.v20120302
jetty-7.6.2.v20120308
jetty-7.6.3.v20120413
jetty-7.6.3.v20120416
jetty-7.6.4.v20120522
jetty-7.6.4.v20120524
jetty-7.6.5.v20120713
jetty-7.6.5.v20120716
jetty-7.6.6.v20120903
jetty-7.6.7.v20120910
jetty-7.6.8.v20121106
jetty-7.6.9.v20130131
jetty-8.*
jetty-8.0.0.RC0
jetty-8.0.0.v20110901
jetty-8.0.1.v20110907
jetty-8.0.1.v20110908
jetty-8.0.2.v20111006
jetty-8.0.3.v20111011
jetty-8.0.4.v20111024
jetty-8.1.0.RC0
jetty-8.1.0.RC1
jetty-8.1.0.RC2
jetty-8.1.0.RC4
jetty-8.1.0.RC5
jetty-8.1.0.v20120125
jetty-8.1.0.v20120127
jetty-8.1.1.v20120215
jetty-8.1.10.v20130312
jetty-8.1.11.v20130520
jetty-8.1.12.v20130725
jetty-8.1.12.v20130726
jetty-8.1.13.v20130910
jetty-8.1.13.v20130916
jetty-8.1.2.v20120302
jetty-8.1.2.v20120308
jetty-8.1.3.v20120413
jetty-8.1.3.v20120416
jetty-8.1.4.v20120522
jetty-8.1.4.v20120524
jetty-8.1.5.v20120713
jetty-8.1.5.v20120716
jetty-8.1.6.v20120903
jetty-8.1.7.v20120910
jetty-8.1.8.v20121106
jetty-8.1.9.v20130131
jetty-9.*
jetty-9.0.0.M0
jetty-9.0.0.M1
jetty-9.0.0.M2
jetty-9.0.0.M3
jetty-9.0.0.M4
jetty-9.0.0.M5
jetty-9.0.0.RC0
jetty-9.0.0.RC1
jetty-9.0.0.RC2
jetty-9.0.0.RC3
jetty-9.0.0.v20130308
jetty-9.0.1.v20130408
jetty-9.0.2.v20130417
jetty-9.0.2.v20140415
jetty-9.0.3.v20130506
jetty-9.0.4.v20130621
jetty-9.0.4.v20130625
jetty-9.0.5.v20130813
jetty-9.0.5.v20130815
jetty-9.0.6.v20130919
jetty-9.0.6.v20130930
npn-api-1.*
npn-api-1.0.0.v20120402
npn-api-1.1.0.v20120525

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-45105.json"
github.com/python/cpython

Affected ranges

Type
GIT
Repo
https://github.com/python/cpython
Events

Affected versions

v2.*
v2.0
v2.1
v2.1a1
v2.1a2
v2.1b1
v2.1b2
v2.1c1
v2.1c2
v2.2a3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-45105.json"