CVE-2021-44228

ENISA EUVD: EUVD-2021-34768 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 43 articles Published: 2021-12-10

EPSS Score

Source: FIRST.org · 2026-05-23
94.45%
probability
This CVE has a 94.45% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
10
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2 (legacy)

9.3
HIGH
Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

VulnerabilityLookup (CNA)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Affected Products

Apache Software Foundation
Apache Log4j2
2.0-beta9

Attack Intelligence

Exploits & PoC

fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

3432 2022-11-23
kozmer/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

1848 2024-02-12
christophetd/log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

1144 2024-04-26
Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

950 2022-01-15
logpresso/CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

861 2022-04-07
f0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

841 2023-06-13
mergebase/log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any

640 2022-03-10
corretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

496 2022-10-24
jas502n/Log4j2-CVE-2021-44228

Remote Code Injection In Log4j

470 2022-01-18
fox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

439 2022-12-27
0xInfection/LogMePwn

A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.

395 2024-12-11
Diverto/nse-log4shell

Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)

352 2021-12-20
CERTCC/CVE-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

350 2022-03-23
back2root/log4shell-rex

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

293 2021-12-21
rubo77/log4j_checker_beta

a fast check, if your server could be vulnerable to CVE-2021-44228

249 2022-01-21
NS-Sp4ce/Vm4J

A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager

209 2022-01-24
takito1812/log4j-detect

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

195 2021-12-13
HyCraftHD/Log4J-RCE-Proof-Of-Concept

Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information

182 2021-12-16
alexandre-lavoie/python-log4rce

An All-In-One Pure Python PoC for CVE-2021-44228

178 2021-12-16
puzzlepeaches/Log4jUnifi

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

167 2024-01-04
mubix/CVE-2021-44228-Log4Shell-Hashes

Hashes for vulnerable LOG4J versions

155 2021-12-17
BinaryDefense/log4j-honeypot-flask

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

151 2021-12-20
NorthwaveSecurity/log4jcheck

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

126 2021-12-14
boundaryx/cloudrasp-log4j2

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

125 2021-12-11
simonis/Log4jPatch

Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process

108 2021-12-12
Adikso/minecraft-log4j-honeypot

Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam

106 2021-12-14
puzzlepeaches/Log4jCenter

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

106 2021-12-22
0xDexter0us/Log4J-Scanner

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

102 2021-12-26
MalwareTech/Log4jTools

Tools for investigating Log4j CVE-2021-44228

94 2021-12-23
thomaspatzke/Log4Pot

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

94 2024-11-29
tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

Apache Log4j 远程代码执行

89 2023-05-14
alexbakker/log4shell-tools

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

85 2024-04-07
giterlizzi/nmap-log4shell

Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)

78 2021-12-17
nccgroup/log4j-jndi-be-gone

A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.

72 2022-01-04
cyberxml/log4j-poc

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

72 2022-12-21
LiveOverflow/log4shell

Small example repo for looking into log4j CVE-2021-44228

72 2021-12-24
bigsizeme/Log4j-check

log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload

70 2021-12-13
future-client/CVE-2021-44228

Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)

66 2021-12-12
lucab85/log4j-cve-2021-44228

Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution -

57 2022-01-10
authomize/log4j-log4shell-affected

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security r

53 2021-12-19
CreeperHost/Log4jPatcher

A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with

49 2022-11-10
CodeShield-Security/Log4JShell-Bytecode-Detector

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

48 2022-02-23
dtact/divd-2021-00038--log4j-scanner

Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-dept

46 2021-12-28
redhuntlabs/Log4JHunt

An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.

46 2025-01-22
1lann/log4shelldetect

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class p

45 2022-01-05
stripe/log4j-remediation-tools

Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)

40 2025-12-19
HynekPetrak/log4shell-finder

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-202

39 2023-06-21
infiniroot/nginx-mitigate-log4shell

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

38 2021-12-15
Y0-kan/Log4jShell-Scan

log4j2 RCE漏洞(CVE-2021-44228)内网扫描器,可用于在不出网的条件下进行漏洞扫描,帮助企业内部快速发现Log4jShell漏洞。

38 2021-12-21
fireeye/CVE-2021-44228

OpenIOC rules to facilitate hunting for indicators of compromise

37 2022-01-07
hackinghippo/log4shell_ioc_ips

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

37 2022-01-07
greymd/CVE-2021-44228

Vulnerability CVE-2021-44228 checker

35 2021-12-13
darkarnium/Log4j-CVE-Detect

Detections for CVE-2021-44228 inside of nested binaries

35 2021-12-18
sassoftware/loguccino

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

33 2022-01-24
Jeromeyoung/log4j2burpscanner

CVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名

32 2021-12-11
twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

Spring Boot Log4j - CVE-2021-44228 Docker Lab

28 2021-12-17
qingtengyun/cve-2021-44228-qingteng-online-patch

Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.

25 2022-01-19
r3kind1e/Log4Shell-obfuscated-payloads-generator

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

25 2022-05-26
toramanemre/log4j-rce-detect-waf-bypass

A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads

23 2021-12-11
mufeedvh/log4jail

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

23 2021-12-14
pedrohavay/exploit-CVE-2021-44228

This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).

20 2021-12-13
Glease/Healer

Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2

19 2023-01-27
corelight/cve-2021-44228

Log4j Exploit Detection Logic for Zeek

19 2025-11-25
faisalfs10x/Log4j2-CVE-2021-44228-revshell

Log4j2 CVE-2021-44228 revshell, ofc it suck!!

18 2021-12-21
blake-fm/vcenter-log4j

Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228

17 2021-12-15
lhotari/log4shell-mitigation-tester

Log4Shell CVE-2021-44228 mitigation tester

16 2021-12-13
Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228

16 2021-12-19
mitiga/log4shell-cloud-scanner

we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in the

14 2021-12-17
ossie-git/log4shell_sentinel

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

14 2021-12-22
xsultan/log4jshield

Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher

13 2021-12-23
snow0715/log4j-Scan-Burpsuite

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

13 2022-01-26
Hydragyrum/evil-rmi-server

An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228

12 2021-12-12
Nanitor/log4fix

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

12 2021-12-24
rakutentech/jndi-ldap-test-server

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

11 2021-12-13
thecyberneh/Log4j-RCE-Exploiter

Scanner for Log4j RCE CVE-2021-44228

11 2022-07-06
claranet/ansible-role-log4shell

Find Log4Shell CVE-2021-44228 on your system

11 2024-06-20
roxas-tan/CVE-2021-44228

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

10 2021-12-16
Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs

Public IoCs about log4j CVE-2021-44228

9 2021-12-17
wortell/log4j

Repo containing all info, scripts, etc. related to CVE-2021-44228

9 2021-12-29
kubearmor/log4j-CVE-2021-44228

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

9 2021-12-15
obscuritylabs/log4shell-poc-lab

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

9 2021-12-17
immunityinc/Log4j-JNDIServer

This project will help to test the Log4j CVE-2021-44228 vulnerability.

9 2021-12-22
Tai-e/CVE-2021-44228

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

9 2025-04-01
sunnyvale-it/CVE-2021-44228-PoC

CVE-2021-44228 (Log4Shell) Proof of Concept

8 2021-12-13
atnetws/fail2ban-log4j

fail2ban filter that catches attacks againts log4j CVE-2021-44228

8 2022-01-06
lfama/log4j_checker

Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.

8 2021-12-21
DXC-StrikeForce/Burp-Log4j-HammerTime

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

8 2021-12-16
Labout/log4shell-rmi-poc

A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI

8 2021-12-19
cybersecurityworks553/log4j-shell-csw

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

8 2021-12-24
7 2021-12-17
OopsieWoopsie/mc-log4j-patcher

CVE-2021-44228 server-side fix for minecraft servers.

7 2021-12-10
Azeemering/CVE-2021-44228-DFIR-Notes

CVE-2021-44228 DFIR Notes

7 2021-12-14
momos1337/Log4j-RCE

Log4j RCE - (CVE-2021-44228)

7 2021-12-13
0xsyr0/Log4Shell

This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.

7 2025-03-20
KeysAU/Get-log4j-Windows.ps1

Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228

7 2021-12-20
mschmnet/Log4Shell-demo

Demo to show how Log4Shell / CVE-2021-44228 vulnerability works

7 2021-12-23
r00thunter/Log4Shell

Generic Scanner for Apache log4j RCE CVE-2021-44228

7 2021-12-22
TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability

7 2021-12-23
marcourbano/CVE-2021-44228

PoC for CVE-2021-44228.

7 2022-09-22
DragonSurvivalEU/RCE

CVE-2021-44228 fix

6 2021-12-20
irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device

6 2021-12-15
ssl/scan4log4j

Python script that sends CVE-2021-44228 log4j payload requests to url list

6 2021-12-12
justakazh/Log4j-CVE-2021-44228

Mass Check Vulnerable Log4j CVE-2021-44228

6 2021-12-13
AlexandreHeroux/Fix-CVE-2021-44228

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/

6 2021-12-15
isuruwa/Log4j

A scanner and a proof of sample exploit for log4j RCE CVE-2021-44228

6 2022-08-06
demining/Log4j-Vulnerability

Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can expl

6 2023-01-31
jacobtread/L4J-Vuln-Patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating

5 2021-12-15
winnpixie/log4noshell

A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").

5 2025-04-28
phoswald/sample-ldap-exploit

A short demo of CVE-2021-44228

5 2021-12-13
5 2021-12-12
mrlnstk/cve-2021-44228-minecraft-poc

Log4J CVE-2021-44228 Minecraft PoC

5 2021-12-12
OlafHaalstra/log4jcheck

Check list of URLs against Log4j vulnerability CVE-2021-44228

5 2021-12-20
manuel-alvarez-alvarez/log4j-cve-2021-44228

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

5 2021-12-21
suuhm/log4shell4shell

Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell

5 2021-12-23
ankur-katiyar/log4j-docker

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)

5 2021-12-20
KeysAU/Get-log4j-Windows-local

Identifying all log4j components across on local windows servers. CVE-2021-44228

5 2021-12-19
snapattack/damn-vulnerable-log4j-app

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

5 2021-12-20
many-fac3d-g0d/apache-tomcat-log4j

Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat

5 2021-12-24
nkoneko/VictimApp

Vulnerable to CVE-2021-44228. trustURLCodebase is not required.

4 2021-12-10
4 2021-12-13
corneacristian/Log4J-CVE-2021-44228-RCE

Log4J (CVE-2021-44228) Exploit with Remote Command Execution (RCE)

4 2021-12-12
0xRyan/log4j-nullroute

Ingest GreyNoise.io malicious feed for CVE-2021-44228 and apply null routes

4 2021-12-14
4 2021-12-14
sinakeshmiri/log4jScan

simple python scanner to check if your network is vulnerable to CVE-2021-44228

4 2021-12-13
Koupah/MC-Log4j-Patcher

A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).

4 2022-01-16
Occamsec/log4j-checker

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.

4 2021-12-16
toramanemre/apache-solr-log4j-CVE-2021-44228

A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228

4 2021-12-14
dbzoo/log4j_scanner

Fast filesystem scanner for CVE-2021-44228

4 2022-01-10
inettgmbh/checkmk-log4j-scanner

Scans for Log4j versions effected by CVE-2021-44228

4 2024-05-13
michaelsanford/Log4Shell-Honeypot

Dockerized honeypot for CVE-2021-44228.

4 2025-08-20
shamo0/CVE-2021-44228

log4shell (CVE-2021-44228) scanning tool

4 2021-12-16
Kr0ff/CVE-2021-44228

Log4Shell Proof of Concept (CVE-2021-44228)

4 2022-04-21
TheInterception/Log4J-Simulation-Tool

Vulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104

4 2021-12-25
lucab85/ansible-role-log4shell

Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).

4 2022-01-10
yesspider-hacker/log4j-payload-generator

log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228

4 2021-12-27
MrHarshvardhan/PY-Log4j-RCE-Scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

4 2023-06-29
zlepper/CVE-2021-44228-Test-Server

A small server for verifing if a given java program is succeptibel to CVE-2021-44228

3 2021-12-10
alexandreroman/cve-2021-44228-workaround-buildpack

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

3 2021-12-10
saharNooby/log4j-vulnerability-patcher-agent

Fixes CVE-2021-44228 in log4j by patching JndiLookup class

3 2021-12-11
unlimitedsola/log4j2-rce-poc

A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).

3 2021-12-12
irgoncalves/f5-waf-quick-patch-cve-2021-44228

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

3 2022-05-04
madCdan/JndiLookup

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228

3 2021-12-13
threatmonit/Log4j-IOCs

Public IOCs about log4j CVE-2021-44228

3 2021-12-13
codiobert/log4j-scanner

Check CVE-2021-44228 vulnerability

3 2021-12-15
mss/log4shell-hotfix-side-effect

Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions

3 2021-12-18
pmontesd/log4j-cve-2021-44228

Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell

3 2021-12-15
ubitech/cve-2021-44228-rce-poc

A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)

3 2021-12-15
Joefreedy/Log4j-Windows-Scanner

CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.

3 2022-10-05
badb33f/Apache-Log4j-POC

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

3 2021-12-22
hotpotcookie/CVE-2021-44228-white-box

Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting c

3 2023-09-06
Sma-Das/Log4j-PoC

An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft

3 2023-03-14
KirkDJohnson/Wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the

3 2024-05-22
tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

3 2024-06-14
1in9e/Apache-Log4j2-RCE

Apache Log4j2 RCE( CVE-2021-44228)验证环境

2 2021-12-10
binganao/Log4j2-RCE

Log4j2 CVE-2021-44228 复现和回显利用

2 2021-12-11
mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform

A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228

2 2021-12-11
jeffbryner/log4j-docker-vaccine

docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228

2 2021-12-12
mzlogin/CVE-2021-44228-Demo

Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP

2 2021-12-12
tasooshi/horrors-log4shell

A micro lab for CVE-2021-44228 (log4j)

2 2022-02-22
dotPY-hax/log4py

pythonic pure python RCE exploit for CVE-2021-44228 log4shell

2 2021-12-12
ph0lk3r/anti-jndi

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

2 2021-12-13
avwolferen/Sitecore.Solr-log4j-mitigation

This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228

2 2022-10-19
kek-Sec/log4j-scanner-CVE-2021-44228

Simple tool for scanning entire directories for attempts of CVE-2021-44228

2 2021-12-14
jeffli1024/log4j-rce-test

CVE-2021-44228 - Apache log4j RCE quick test

2 2021-12-13
perryflynn/find-log4j

Find log4j for CVE-2021-44228 on some places * Log4Shell

2 2021-12-14
alpacamybags118/log4j-cve-2021-44228-sample

Sample docker-compose setup to show how this exploit works

2 2022-01-14
VinniMarcon/Log4j-Updater

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

2 2021-12-15
anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228

A one-stop repo/ information hub for all log4j vulnerability-related information.

2 2022-01-14
alenazi90/log4j

An automated header extensive scanner for detecting log4j RCE CVE-2021-44228

2 2021-12-15
korteke/log4shell-demo

Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)

2 2023-02-13
Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

2 2022-01-13
spasam/log4j2-exploit

log4j2 Log4Shell CVE-2021-44228 proof of concept

2 2021-12-20
julian911015/Log4j-Scanner-Exploit

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.

2 2024-09-03
chandru-gunasekaran/log4j-fix-CVE-2021-44228

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

2 2021-12-23
2 2022-03-28
Vulnmachines/log4jshell_CVE-2021-44228

Log4jshell - CVE-2021-44228

2 2022-07-26
dcm2406/CVE-Lab

Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604

2 2024-03-20
lathika-3006/Solar-exploiting-log-4j

This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the

2 2026-03-22
lhotari/pulsar-docker-images-patch-CVE-2021-44228

Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell

1 2022-01-13
uint0/cve-2021-44228--spring-hibernate

CVE-2021-44228 POC - Spring / Hibernate

1 2021-12-11
cado-security/log4shell

Content to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228

1 2021-12-11
RrUZi/Awesome-CVE-2021-44228

An awesome curated list of repos for CVE-2021-44228. ``Apache Log4j 2``

1 2021-12-12
kali-dass/CVE-2021-44228-log4Shell

Sample log4j shell exploit

1 2021-12-13
kimobu/cve-2021-44228

Some files for red team/blue team investigations into CVE-2021-44228

1 2021-12-14
halibobor/log4j2

CVE-2021-44228

1 2021-12-13
sourcegraph/log4j-cve-code-search-resources

Using code search to help fix/mitigate log4j CVE-2021-44228

1 2024-04-01
JiuBanSec/Log4j-CVE-2021-44228

Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)

1 2021-12-13
p3dr16k/log4j-1.2.15-mod

log4j version 1 with a patch for CVE-2021-44228 vulnerability

1 2021-12-14
Woahd/log4j-urlscanner

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading

1 2021-12-15
gcmurphy/chk_log4j

Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

1 2021-12-14
guerzon/log4shellpoc

Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)

1 2021-12-17
rgl/log4j-log4shell-playground

A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations

1 2021-12-15
dpomnean/log4j_scanner_wrapper

log4j vulnerability wrapper scanner for CVE-2021-44228

1 2021-12-16
andalik/log4j-filescan

Scanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de

1 2022-03-05
gyaansastra/CVE-2021-44228

Log4Shell CVE-2021-44228 Vulnerability Scanner and POC

1 2021-12-21
kal1gh0st/MyLog4Shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

1 2021-12-30
Aschen/log4j-patched

Provide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself

1 2021-12-17
Apipia/log4j-pcap-activity

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

1 2021-12-18
trickyearlobe/inspec-log4j

An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046

1 2021-12-19
Rk-000/Log4j_scan_Advance

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

1 2021-12-19
mn-io/log4j-spring-vuln-poc

POC for CVE-2021-44228 within Springboot

1 2021-12-22
MarceloLeite2604/log4j-vulnerability

Presents how to exploit CVE-2021-44228 vulnerability.

1 2022-01-03
TPower2112/Writing-Sample-1

CVE-2021-44228 Log4j Summary

1 2022-11-19
moshuum/tf-log4j-aws-poc

This project files demostrate a proof-of-concept of log4j vulnerability (CVE-2021-44228) on AWS using Terraform Infrastructure-as-a-code means.

1 2022-06-08
jaehnri/CVE-2021-44228

Proof of concept of the Log4Shell vulnerability (CVE-2021-44228)

1 2022-07-07
bcdunbar/CVE-2021-44228-poc

CVE-2021-44228 POC / Example

1 2022-09-29
srcporter/CVE-2021-44228

DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"

1 2024-08-22
pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

1 2023-02-08
demonrvm/Log4ShellRemediation

A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105

1 2023-04-04
sec13b/CVE-2021-44228-POC

exploit CVE-2021-44228

1 2024-11-06
Carlos-Mesquita/TPASLog4ShellPoC

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's de

1 2024-10-08
danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-

Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.

1 2026-03-26
dbgee/CVE-2021-44228

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

0 2022-01-19
izzyacademy/log4shell-mitigation

Mitigation for Log4Shell Security Vulnerability CVE-2021-44228

0 2021-12-11
Kadantte/CVE-2021-44228-poc

log4shell sample application (CVE-2021-44228)

0 2021-12-10
gauthamg/log4j2021_vul_test

Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228

0 2021-12-13
leetxyz/CVE-2021-44228-Advisories

List of company advisories log4j

0 2021-12-12
WYSIIWYG/Log4J_0day_RCE

Log4j-RCE (CVE-2021-44228) Proof of Concept

0 2021-12-11
datadavev/test-44228

Simple demo of CVE-2021-44228

0 2022-01-04
LemonCraftRu/JndiRemover

Небольшой мод направленный на устранение уязвимости CVE-2021-44228

0 2022-02-07
zhangxvx/Log4j-Rec-CVE-2021-44228

Apache Log4j CVE-2021-44228 漏洞复现

0 2021-12-12
Crane-Mocker/log4j-poc

Poc of log4j2 (CVE-2021-44228)

0 2021-12-12
urholaukkarinen/docker-log4shell

Dockerized Go app for testing the CVE-2021-44228 vulnerability

0 2021-12-12
guardicode/CVE-2021-44228_IoCs

Known IoCs for log4j framework vulnerability

0 2022-01-18
fireflyingup/log4j-poc

CVE-2021-44228 test demo

0 2021-12-13
markuman/aws-log4j-mitigations

CVE-2021-44228 log4j mitigation using aws wafv2 with ansible

0 2021-12-13
tuyenee/Log4shell

A lab for playing around with the Log4J CVE-2021-44228

0 2021-12-13
Camphul/log4shell-spring-framework-research

Research into the implications of CVE-2021-44228 in Spring based applications.

0 2021-12-15
0 2021-12-13
1hakusai1/log4j-rce-CVE-2021-44228

log4j2 CVE-2021-44228 POC

0 2021-12-13
VNYui/CVE-2021-44228

Mass recognition tool for CVE-2021-44228

0 2021-12-13
kossatzd/log4j-CVE-2021-44228-test

demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability

0 2021-12-24
0 2021-12-23
yanghaoi/CVE-2021-44228_Log4Shell

Log4Shell A test for CVE-2021-44228

0 2021-12-13
ben-smash/l4j-info

Compiling links of value i find regarding CVE-2021-44228

0 2021-12-13
strawhatasif/log4j-test

Demonstration of CVE-2021-44228 with a possible strategic fix.

0 2021-12-13
chilit-nl/log4shell-example

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

0 2021-12-14
snatalius/log4j2-CVE-2021-44228-poc-local

Just a personal proof of concept of CVE-2021-44228 on log4j2

0 2021-12-13
Contrast-Security-OSS/CVE-2021-44228

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

0 2026-05-04
sandarenu/log4j2-issue-check

Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228

0 2021-12-14
cbuschka/log4j2-rce-recap

Little recap of the log4j2 remote code execution (CVE-2021-44228)

0 2021-12-14
andrii-kovalenko-celonis/log4j-vulnerability-demo

Endpoint to test CVE-2021-44228 – Log4j 2

0 2021-12-14
dark-ninja10/Log4j-CVE-2021-44228

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution

0 2021-12-14
34zY/JNDI-Exploit-1.2-log4shell

Details : CVE-2021-44228

0 2021-12-19
0xThiebaut/CVE-2021-44228

CVE-2021-44228 Response Scripts

0 2021-12-15
jeremyrsellars/CVE-2021-44228_scanner

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

0 2021-12-15
bhprin/log4j-vul

This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228

0 2023-01-31
jyotisahu98/logpresso-CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

0 2021-12-15
MeterianHQ/log4j-vuln-coverage-check

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

0 2022-12-01
0 2021-12-15
honeynet/log4shell-data

Data we are receiving from our honeypots about CVE-2021-44228

0 2021-12-16
b1tm0n3r/CVE-2021-44228

CVE-2021-44228 demo webapp

0 2021-12-20
rv4l3r3/log4v-vuln-check

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

0 2021-12-20
recanavar/vuln_spring_log4j2

Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

0 2021-12-16
lonecloud/CVE-2021-44228-Apache-Log4j

CVE-2021-44228-Apache-Log4j

0 2021-12-16
axisops/CVE-2021-44228

log4j mitigation work

0 2025-07-02
hozyx/log4shell

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the pres

0 2021-12-16
andypitcher/Log4J_checker

Log4J checker for Apache CVE-2021-44228

0 2021-12-16
wajda/log4shell-test-exploit

Test exploit of CVE-2021-44228

0 2021-12-23
Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE

PoC RCE Log4j CVE-2021-4428 para pruebas

0 2022-01-04
sysadmin0815/Fix-Log4j-PowershellScript

Log4Shell mitigation (CVE-2021-44228) - search and remove JNDI class from *log4j*.jar files on the system with Powershell (Windows)

0 2021-12-23
RenYuH/log4j-lookups-vulnerability

Log4j2 Vulnerability (CVE-2021-44228)

0 2021-12-17
scheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

0 2021-12-17
zaneef/CVE-2021-44228

Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione

0 2021-12-21
metodidavidovic/log4j-quick-scan

Scan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.

0 2021-12-21
WatchGuard-Threat-Lab/log4shell-iocs

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

0 2021-12-17
nikolas-charalambidis/cve-2021-44228

A simple simulation of the infamous CVE-2021-44228 issue.

0 2021-12-18
0 2021-12-20
DANSI/PowerShell-Log4J-Scanner

can find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046

0 2022-03-29
suniastar/scan-log4shell

A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it

0 2021-12-18
shivakumarjayaraman/log4jvulnerability-CVE-2021-44228

An attempt to understand the log4j vulnerability by looking through the code

0 2021-12-18
j3kz/CVE-2021-44228-PoC

Self-contained lab environment that runs the exploit safely, all from docker compose

0 2021-12-18
axelcurmi/log4shell-docker-lab

Log4Shell (CVE-2021-44228) docker lab

0 2021-12-24
otaviokr/log4j-2021-vulnerability-study

This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it wo

0 2022-01-22
TotallyNotAHaxxer/f-for-java

a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD

0 2022-12-16
0 2021-12-21
r00thunter/Log4Shell-Scanner

Python script to detect Log4Shell Vulnerability CVE-2021-44228

0 2021-12-21
rejupillai/log4j2-hack-springboot

Log4j2 CVE-2021-44228 hack demo for a springboot app

0 2023-03-22
ssl-user-en/Log4j-Scanner-Exploit

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.

0 2021-12-21
BJLIYANLIANG/log4j-scanner

Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS

0 2021-12-19
grimch/log4j-CVE-2021-44228-workaround

general purpose workaround for the log4j CVE-2021-44228 vulnerability

0 2021-12-24
Toolsec/log4j-scan

CVE-2021-44228 检查工具

0 2021-12-24
bsigouin/log4shell-vulnerable-app

Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.

0 2023-01-20
ToxicEnvelope/XSYS-Log4J2Shell-Ex

this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research

0 2021-12-27
felipe8398/ModSec-log4j2

Regra ModSec para proteção log4j2 - CVE-2021-44228

0 2022-03-10
0 2021-12-27
mazhar-hassan/log4j-vulnerability

Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j

0 2022-08-23
xungzzz/VTI-IOCs-CVE-2021-44228

IOCs for CVE-2021-44228

0 2021-12-27
s-retlaw/l4s_poc

Log4Shell (Cve-2021-44228) Proof Of Concept

0 2023-07-25
LinkMJB/log4shell_scanner

Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability

0 2021-12-27
PoneyClairDeLune/LogJackFix

A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.

0 2021-12-28
romanutti/log4shell-vulnerable-app

This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.

0 2022-05-10
mklinkj/log4j2-test

Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)

0 2024-01-13
aajuvonen/log4stdin

A Java application intentionally vulnerable to CVE-2021-44228

0 2023-03-17
s-retlaw/l4srs

Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)

0 2023-01-14
Phineas09/CVE-2021-44228

Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc

0 2022-05-13
ra890927/Log4Shell-CVE-2021-44228-Demo

Log4Shell CVE-2021-44228 Demo

0 2022-06-13
vino-theva/CVE-2021-44228

Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell vulnerability and how it works, how it affects the

0 2022-08-02
eurogig/jankybank

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

0 2024-03-12
digital-dev/Log4j-CVE-2021-44228-Remediation

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple

0 2024-01-26
ocastel/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

0 2022-09-21
53buahapel/log4shell-vulnweb

this web is vulnerable against CVE-2021-44228

0 2023-04-03
funcid/log4j-exploit-fork-bomb

💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228

0 2023-05-02
roshanshibu/Odysseus

A demo of the Log4Shell (CVE-2021-44228) vulnerability.

0 2023-11-14
LucasPDiniz/CVE-2021-44228

Log4j Vulnerability RCE - CVE-2021-44228

0 2024-06-30
felixslama/log4shell-minecraft-demo

Log4Shell (CVE-2021-44228) minecraft demo. Used for education fairs

0 2023-11-21
0 2024-07-15
scabench/l4j-tp1

jee web project with log4shell (CVE-2021-44228) vulnerability

0 2024-01-09
scabench/l4j-fp1

jee web project with sanitised log4shell (CVE-2021-44228) vulnerability

0 2024-01-14
KtokKawu/l4s-vulnapp

This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).

0 2024-03-15
NikitaPark/Log4Shell-PoC-Application

Log4Shell (CVE-2021-44228) PoC Application

0 2024-10-10
asd58584388/CVE-2021-44228

CVE-2021-44228 vulnerability study

0 2024-07-26
safeer-accuknox/log4j-shell-poc

Log4J exploit CVE-2021-44228

0 2024-09-11
AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-

In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-u

0 2024-11-10
Super-Binary/cve-2021-44228

这是安徽大学 “漏洞分析实验”(大三秋冬)期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/

0 2024-11-23
0 2025-01-20
yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-

This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to dete

0 2025-02-17
0 2025-03-13
timothyjxhn/DeliberatelyVulnerableWebApp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 W

0 2025-04-15
0 2025-04-14
Fauzan-Aldi/Log4j-_Vulnerability

The Web Is Vulnerable to CVE-2021-44228

0 2025-05-08
SerpilRivas/log4shell-homework9

Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident

0 2025-05-27
x1ongsec/CVE-2021-44228-Log4j-JNDI

CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境

0 2025-06-21
fabioeletto/hka-seminar-log4shell

Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)

0 2025-07-11
Sorrence/CVE-2021-44228

A simple Log4j PoC written in Go

0 2025-10-05
moften/Log4Shell

Log4Shell CVE-2021-44228 PoC

0 2025-09-09
KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling de

0 2025-09-27
arabindadora/log4shell

Log4Shell (CVE-2021-44228) PoC

0 2025-09-29
Mintimate/log4j2-bugmaker

Demo of CVE-2021-44228 Log4Shell.

0 2025-10-28
mgueye3/Log4Shell

This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a saf

0 2025-11-16
PCMKUIT/CVE-2021-44228---Log4Shell-Analysis

Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), a

0 2025-11-18
DrHaitham/Log4Shell-CVE-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and de

0 2025-12-06
Loliverte/Log4j-Vulnerability

Étude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé

0 2025-12-14
JoseMariaMicoli/Log4Shell-PoC

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sand

0 2026-01-14
agylabs/log4shell-remediation

Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java

0 2026-02-05
0 2026-03-05
Codepumpking/log4shell-poc

POC for log4shll Vulnerablity (CVE-2021-44228)

0 2026-03-15
wmohamed2033/wmohamed2033.github.io

CVE-2021-44228 Log4Shell — Penetration Test Writeup

0 2026-03-17
Saru1718/THM---Solar-exploiting-Log-4j

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attacker

0 2026-03-22
Lavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vuln

0 2026-03-22
jdormannn/SecureOps-Lab

Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force

0 2026-04-14
0 2026-04-10
pinaraltinok/Log4Shell-Attack

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

0 2026-04-22
tieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

0 2026-04-28
0 2026-05-02
neilc1964techned/craready-test-java-vulns

CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs

0 2026-05-02
FacundoMfernandez/pentesting-obioba

Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico

0 2026-05-05
aaronm-sysdig/log4j-vuln-demo

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

0 2026-05-19
MAFO-sec/mi-laboratorio-log4shell

Laboratorio automatizado Plug & Play en Docker para auditar y estudiar la vulnerabilidad Log4Shell (CVE-2021-44228)

0 2026-05-18
407 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 94.45%
CVSS v3.1 10
Mentions 43
Last Seen Dec 12, 2025

CNA Information

CNA Assigner
apache
CNA Title
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Analyst Note

CVE-2021-44228 (Log4Shell) is the canonical zero-day vulnerability of 2021. It was publicly disclosed on 2021-12-10 and immediately exploited in the wild across thousands of organizations before patches were widely available. Exploitation preceded patch deployment by weeks, and this vulnerability defined zero-day exploitation in 2021-2022. The articles reference immediate, widespread real-world attacks following disclosure.

Threat Actors 69

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 41
apt_group Information theft and espionage 🇨🇳 CN
Turla Group
apt_group Information theft and espionage Russian Federation
Void Arachne
apt_group Information theft and espionage 🇨🇳 CN
APT 29
apt_group Information theft and espionage 🇷🇺 RU
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
Prophet Spider
apt_group UNKNOWN
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
TA800
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Kinsing
apt_group 🇷🇺 RU
Operation C-Major
apt_group Information theft and espionage 🇵🇰 PK
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
TA505
apt_group Financial gain 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
SideCopy
apt_group Information theft and espionage 🇵🇰 PK
Group 27
apt_group Information theft and espionage 🇨🇳 CN
TeamTNT
apt_group 🇩🇪 DE
TA428
apt_group Information theft and espionage 🇨🇳 CN
GhostR
apt_group 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
TA413
apt_group Information theft and espionage 🇨🇳 CN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
TAG-28
apt_group Information theft and espionage 🇨🇳 CN
Earth Estries
apt_group Information theft and espionage 🇨🇳 CN
HAFNIUM
apt_group Information theft and espionage 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
APT31
apt_group Information theft and espionage 🇨🇳 CN
Returned Libra
apt_group 🇨🇳 CN
POLONIUM
apt_group Information theft and espionage 🇱🇧 LB
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Storm-0530
apt_group 🇰🇵 KP
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Earth Longzhi
apt_group 🇨🇳 CN
UAC-0184
apt_group 🇺🇦 UA
Hezb
apt_group Information theft and espionage 🇱🇧 LB
BRONZE STARLIGHT
apt_group Information theft and espionage 🇨🇳 CN
CyberAv3ngers
apt_group Sabotage and destruction 🇮🇷 IR
Red October
apt_group 🇷🇺 RU
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Test Panda
apt_group 🇨🇳 CN
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
TA2552
apt_group Information theft and espionage 🇮🇷 IR
Magic Kitten
apt_group Information theft and espionage 🇮🇷 IR
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Poisonous Panda
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Scarred Manticore
apt_group Information theft and espionage 🇮🇷 IR
Operation Dragon Castling
apt_group Information theft and espionage 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
PlushDaemon
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Dark Partners
apt_group

Triage Info

Decided atMar 05, 2026
Published DateDec 10, 2021