Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
Update org.apache.logging.log4j:log4j-core to 2.12.3; org.apache.logging.log4j:log4j-core to 2.17.0; org.apache.logging.log4j:log4j-core to 2.3.1; org.ops4j.pax.logging:pax-logging-log4j2 to 1.9.2; org.ops4j.pax.logging:pax-logging-log4j2 to 1.10.9; org.ops4j.pax.logging:pax-logging-log4j2 to 1.11.12; org.ops4j.pax.logging:pax-logging-log4j2 to 2.0.13 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion affects org.apache.logging.log4j:log4j-core (maven), org.apache.logging.log4j:log4j-core (maven), org.apache.logging.log4j:log4j-core (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven). Severity is high. Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.logging.log4j:log4j-coremaven | >=2.4.0,<2.12.3 | 2.12.3 |
| org.apache.logging.log4j:log4j-coremaven | >=2.13.0,<2.17.0 | 2.17.0 |
| org.apache.logging.log4j:log4j-coremaven | <2.3.1 | 2.3.1 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.8.0,<1.9.2 | 1.9.2 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.10.0,<1.10.9 | 1.10.9 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.11.0,<1.11.12 | 1.11.12 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=2.0.0,<2.0.13 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate org.apache.logging.log4j:log4j-core to 2.12.3; org.apache.logging.log4j:log4j-core to 2.17.0; org.apache.logging.log4j:log4j-core to 2.3.1; org.ops4j.pax.logging:pax-logging-log4j2 to 1.9.2; org.ops4j.pax.logging:pax-logging-log4j2 to 1.10.9; org.ops4j.pax.logging:pax-logging-log4j2 to 1.11.12; org.ops4j.pax.logging:pax-logging-log4j2 to 2.0.13 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion affects org.apache.logging.log4j:log4j-core (maven), org.apache.logging.log4j:log4j-core (maven), org.apache.logging.log4j:log4j-core (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven), org.ops4j.pax.logging:pax-logging-log4j2 (maven). Severity is high. Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3. # Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.logging.log4j:log4j-coremaven | >=2.4.0,<2.12.3 | 2.12.3 |
| org.apache.logging.log4j:log4j-coremaven | >=2.13.0,<2.17.0 | 2.17.0 |
| org.apache.logging.log4j:log4j-coremaven | <2.3.1 | 2.3.1 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.8.0,<1.9.2 | 1.9.2 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.10.0,<1.10.9 | 1.10.9 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=1.11.0,<1.11.12 | 1.11.12 |
| org.ops4j.pax.logging:pax-logging-log4j2maven | >=2.0.0,<2.0.13 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 2.0.13 |
| 2.0.13 |