← All labs

Apache · log4j

CVE-2021-44228

CVE-2021-44228 Apache Log4j Log4Shell controlled lab

REPRODUCED LAB VALIDATED

OVERVIEW

Lab observed

Vulnerable2.14.1
Patched2.17.1

Java runtime
AdoptOpenJDK HotSpot 8u181-b13

Evidence
Vulnerable + Patched Control

Detection
Lab Validated

Primary analytic
ATTEMPT ONLY

Vendor reported

Vendor-reported fixed versions

2.3.1 / 2.12.2 / 2.15.0

Only the lab versions above were independently reproduced by CVE Mapping.

LAB OBSERVED

What this lab demonstrates

One fixed request in vulnerable mode produced an internal support-service lookup, fixed class request, and container-only marker. The equivalent patched request produced no lookup and no marker.

The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.

VULNERABLE VS PATCHED RESULT

VULNERABLE

Runtime accepted and the documented state difference was observed.

PATCHED CONTROL

Runtime accepted and the expected safe state was retained.

CI VALIDATED

Evidence, telemetry, and detection checks are recorded in the manifest.

DETECTION COVERAGE

Detection engineering

  • Sigma1 lab-validated analytic
  • Splunk1 lab-validated analytic
  • Elastic1 lab-validated analytic

Request telemetry provides context, while the strongest analytic requires correlated application-state telemetry. A request alone does not prove exploitation.

FIXTURE DISCRIMINATION

Lab fixture performance

Validated state-change analytics matched vulnerable activity and did not match patched or benign controls. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.

Validated state-change · Vulnerable1 matched
Validated state-change · Patched1 matched
Validated state-change · Benign0 matched
Contextual request · Vulnerable2 matched
Contextual request · Patched0 matched
Contextual request · Benign0 matched

EVIDENCE & TELEMETRY

Preserved and verifiable

Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.

RISK CONTEXT

Vendor enrichment

Additional risk feeds are omitted without a verified current lookup.

MITRE ATT&CK
Unassigned

REPRODUCE LOCALLY

Start with the Quickstart.

Use the repository operator workflow on a disposable, localhost-only environment. The website does not embed proof payload content.

Open Quickstart

LIMITATIONS & SAFETY

Scope stays explicit.

The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.