{"api_version":"v1","generated_at":"2026-10-06T21:30:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-log4j2-4e8f10ce0e82","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Log4j2","next_cursor":null,"observations":[{"affected":"log4j-core < 2.17.1","affected_versions_present":true,"cve_id":"CVE-2021-44832","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-44832","fixed":"Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-29T18:53:46.103Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-44832","primary_source":"","published":"2021-12-28T19:35:11.000Z"},{"affected":"log4j-core < 2.17.0","affected_versions_present":true,"cve_id":"CVE-2021-45105","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-45105","fixed":"Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-29T11:45:26.064Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-45105","primary_source":"","published":"2021-12-18T11:55:08.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
