← All labs

Apache · log4j

CVE-2021-44228

CVE-2021-44228 Apache Log4j Log4Shell controlled lab

REPRODUCED LAB VALIDATED

OVERVIEW

Lab observed

Vulnerable2.14.1
Patched2.17.1

Java runtime
AdoptOpenJDK HotSpot 8u181-b13

Evidence
Vulnerable + Patched Control

Detection
Lab Validated

Primary analytic
ATTEMPT ONLY

Vendor reported

Vendor-reported fixed versions

2.3.1 / 2.12.2 / 2.15.0

Only the lab versions above were independently reproduced by CVE Mapping.

LAB OBSERVED

What this lab demonstrates

One fixed request in vulnerable mode produced an internal support-service lookup, fixed class request, and container-only marker. The equivalent patched request produced no lookup and no marker.

The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.

VULNERABLE VS PATCHED RESULT

VULNERABLE

Runtime accepted and the documented state difference was observed.

PATCHED CONTROL

Runtime accepted and the expected safe state was retained.

CI VALIDATED

Evidence, telemetry, and detection checks are recorded in the manifest.

DETECTION COVERAGE

Detection engineering

  • Sigma1 lab-validated analytic
  • Splunk1 lab-validated analytic
  • Elastic1 lab-validated analytic

Request telemetry provides context, while the strongest analytic requires correlated application-state telemetry. A request alone does not prove exploitation.

Lab queries

Sigma — log4j_jndi_lookup_attempt.yml lab-validated
title: Suspicious Log4j JNDI Lookup Attempt
id: 0c76f4cd-0b95-472a-960e-55f25ad0c7a2
status: test
description: Detects a normalized and sanitized Log4j JNDI lookup-attempt indicator in application request telemetry. This is attempt semantics and does not independently prove successful code execution.
references:
  - https://logging.apache.org/log4j/2.x/security.html
  - https://nvd.nist.gov/vuln/detail/CVE-2021-44228
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: CVE Mapping
date: "2026-08-28"
tags:
  - cve.2021.44228
logsource:
  product: java
  service: normalized_application_request
detection:
  selection:
    event.category: web
    event.type: application_request
    service: log4j-lab
    http.method: POST
    log4j_lookup.attempt_indicator: true
    log4j_lookup.syntax: jndi_lookup_redacted
  condition: selection
falsepositives:
  - Vulnerability scanners, security validation systems, WAF tests, honeypots, research traffic, lab traffic, and literal suspicious strings in logged application data
level: medium

View on GitHub

Splunk — log4j_jndi_lookup_attempt.spl lab-validated
/*
CVE-2021-44228 suspicious Log4j JNDI lookup-attempt analytic.
Expected sourcetype: deployment-specific normalized Java application request
telemetry mapped to the fields used below. This search does not confirm
successful code execution.
*/
event.category="web" event.type="application_request" service="log4j-lab" http.method="POST" log4j_lookup.attempt_indicator=true log4j_lookup.syntax="jndi_lookup_redacted"
| eval analytic="log4j_jndi_lookup_attempt"
| table _time analytic service http.method url.path http.status_code log4j.version java.version lab.mode lab.lookup_observed lab.marker_observed message

View on GitHub

Elastic — log4j_jndi_lookup_attempt.json lab-validated
{
  "name": "Suspicious Log4j JNDI lookup attempt",
  "cve": "CVE-2021-44228",
  "type": "query",
  "language": "kuery",
  "query": "event.category:web and event.type:application_request and service:log4j-lab and http.method:POST and log4j_lookup.attempt_indicator:true and log4j_lookup.syntax:jndi_lookup_redacted",
  "severity": "medium",
  "risk_rationale": "The query identifies sanitized lookup-attempt semantics in normalized application telemetry. It does not prove successful Log4Shell exploitation or code execution.",
  "false_positive_note": "Vulnerability scanners, security validation systems, WAF tests, honeypots, research traffic, lab traffic, and logged literal strings can match.",
  "required_fields": [
    "event.category",
    "event.type",
    "service",
    "http.method",
    "url.path",
    "log4j_lookup.attempt_indicator",
    "log4j_lookup.syntax",
    "message"
  ],
  "references": [
    "https://logging.apache.org/log4j/2.x/security.html",
    "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "fixture_discrimination": {"vulnerable": 1, "patched": 1, "benign": 0}
}

View on GitHub

FIXTURE DISCRIMINATION

Lab fixture performance

Validated state-change analytics matched vulnerable activity; 1 matched the patched control. See the detection validation record for discrimination notes. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.

Validated state-change · Vulnerable1 matched
Validated state-change · Patched1 matched
Validated state-change · Benign0 matched
Contextual request · Vulnerable2 matched
Contextual request · Patched0 matched
Contextual request · Benign0 matched

EVIDENCE & TELEMETRY

Preserved and verifiable

Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.

RISK CONTEXT

Vendor enrichment

Additional risk feeds are omitted without a verified current lookup.

MITRE ATT&CK
Unassigned

COPYABLE RUNBOOK

Start with the Quickstart.

Disposable, localhost-only runbook commands taken from the lab's QUICKSTART.md. Proof internals stay in the repository — these are the operator workflow commands.

Runbook
./scripts/start.sh vulnerable
curl --fail http://127.0.0.1:39428/health
./scripts/collect-baseline.sh vulnerable
./scripts/reset.sh
./scripts/start.sh patched
curl --fail http://127.0.0.1:39428/health
./scripts/collect-baseline.sh patched
./scripts/reset.sh
./scripts/reproduce.sh vulnerable

LIMITATIONS & SAFETY

Scope stays explicit.

The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.