Log4Shell
Sign in to saveAlso known as CVE-2021-44228
Log4Shell (CVE-2021-44228) is a vulnerability reported in November 2021 in Log4j, a popular Java logging framework, involving arbitrary code execution and exploited as a zero-day vulnerability. The vulnerability had existed unnoticed since 2013 and was privately disclosed to the Apache Software Foundation, of which Log4j is a project, by Chen Zhaojun of Alibaba Cloud's security team on 24 November 2021.
Key facts
- Bug.name
- Log4Shell
- Bug.discoverer
- Chen Zhaojun of the Alibaba Cloud Security Team
- Bug.affected software
- Applications logging user input using Log4j 2
via Wikipedia infobox
Wikidata facts
Show 8 more facts
- product or material produced
- arbitrary code execution
- hashtag
- log4shell
- Stack Exchange tag
- stackoverflow.com/tags/log4shell
- discoverer or inventor
- Alibaba Cloud
- depends on software
- Log4j
- announcement date
- 2021-12-09
- time of discovery or invention
- 2021-11-24
via Wikidata · CC0