← All CVEs NewScan detects
medium

CVE-2021-44832

Log4j JDBC Appender remote code execution when an attacker controls the logging configuration

Severity
medium
Affected product
Log4j
Affected versions
Log4j ≥ 2.0, < 2.17.1
Fixed in
Log4j 2.17.1
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Log4j from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →