Yet another Log4j patch hoovers up new remote code execution bug

Security measures
(Image credit: Shutterstock)

Apache has released yet another patch for the now-infamous Log4j utility, which delivers a fix for a new remote code execution vulnerability.

The logging utility has been the center of attention in the cybersecurity community for much of December, after a major vulnerability was discovered that enabled malicious actors with very limited knowledge to run scripts remotely.

This gaping hole has since been patched, but the newer version of the logger came with flaws of its own, albeit not as dangerous as the original. Soon after that vulnerability was patched, yet another issue was discovered. 

With Log4j version 2.17.1., the latest vulnerability (tracked as CVE-2021-44832), has now been fixed. All users have been urged to prioritize the update.

Another Log4j patch

The latest vulnerability is classified as a remote code execution flaw, stemming from the lack of extra controls on JDNI access in Log4j. As BleepingComputer reports, the flaw is rated “Moderate” in severity, and has been assigned a score of 6.6/10 as per the Common Vulnerability Scoring System (CVSS). 

"JDBC Appender should use JndiManager when accessing JNDI. JNDI access should be controlled via a system property," the flaw description explains.

"Related to CVE-2021-44832 where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code."

The original Log4j vulnerability, tracked as CVE-2021-44228, was given the nickname Log4Shell. It allowed crooks to run virtually any code remotely and, given the widespread use of Log4j, quickly became a nightmare for corporations and government organizations around the world.

Jen Easterly, Director of the US Cybersecurity and Infrastructure Security Agency (CISA), described it as “one of the most serious” flaws she’s seen in her entire career, “if not the most serious”.

  • You might also want to check out our list of the best antivirus solutions around today

Via BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Apache Foundation urges users to patch now and fix major security worries
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
vpn
Ivanti warns another critical security flaw is being attacked
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
Latest in Security
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about Avengers: Doomsday's cast on YouTube, and I think it's going to be a long-winded reveal
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch
Microsoft Copiot Studio deep reasoning and agent flows
Microsoft reveals OpenAI-powered Copilot AI agents to bosot your work research and data analysis