Apache Log4j Cores Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:
Users of the SyslogAppender are not affected, as its configuration attributes were not modified.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Log4j | Apache | 2.21.0 (including) | 2.25.4 (excluding) |
| Log4j | Apache | 3.0.0-beta1 (including) | 3.0.0-beta1 (including) |
| Log4j | Apache | 3.0.0-beta2 (including) | 3.0.0-beta2 (including) |
| Log4j | Apache | 3.0.0-beta3 (including) | 3.0.0-beta3 (including) |
| Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 | RedHat | log4j-core | * |
| Red Hat Data Grid 8.6.1 | RedHat | log4j-core | * |
| Red Hat Data Grid 8.6.1 | RedHat | log4j-core-test | * |
| Red Hat Offline Knowledge Portal 1.2.4 | RedHat | offline-knowledge-portal/rhokp-rhel9:1779996999 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-modelmesh-rhel9:1783443816 | * |
| Apache-log4j1.2 | Ubuntu | esm-apps/xenial | * |
| Apache-log4j1.2 | Ubuntu | questing | * |
| Apache-log4j2 | Ubuntu | esm-infra/xenial | * |
| Apache-log4j2 | Ubuntu | questing | * |