{"id":44496,"date":"2021-12-18T18:05:07","date_gmt":"2021-12-18T18:05:07","guid":{"rendered":"http:\/\/59ed1efa-e7ea-4860-b906-03680e127ca9"},"modified":"2021-12-18T18:05:07","modified_gmt":"2021-12-18T18:05:07","slug":"apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","title":{"rendered":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability"},"content":{"rendered":"<p>Apache <a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/security.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">has released version 2.17.0<\/a> of the patch for Log4j after discovering issues with their previous release, which <a href=\"https:\/\/www.zdnet.com\/article\/second-log4j-vulnerability-found-apache-log4j-2-16-0-released\/\" target=\"_blank\" rel=\"noopener\">came out on Tuesday<\/a>.&nbsp;<\/p>\n<p>Apache said version 2.16 &#8220;does not always protect from infinite recursion in lookup evaluation&#8221; and explained that it is vulnerable to&nbsp;<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-45105\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">CVE-2021-45105<\/a>, a denial of service vulnerability. They said the severity is &#8220;high&#8221; and gave it a CVSS score of 7.5.<\/p>\n<p>&#8220;Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DOS (Denial of Service) attack,&#8221; Apache explained.&nbsp;<\/p>\n<p>They added that the latest issue was discovered by Akamai Technologies&#8217; Hideki Okamoto and an anonymous vulnerability researcher.<\/p>\n<p>Mitigations include applying the 2.17.0 patch and replacing Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc, or %MDC) in PatternLayout in the logging configuration. Apache also suggested removing references to Context Lookups in the the configuration like ${ctx:loginId} or $${ctx:loginId} where they originate from sources external to the application such as HTTP headers or user input.<\/p>\n<p>They noted that only the Log4j-core JAR file is impacted by CVE-2021-45105.&nbsp;<\/p>\n<p>On Friday, security researchers online began <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1471943986705281029?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1471943986705281029%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fupgraded-to-log4j-216-surprise-theres-a-217-fixing-dos%2F\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">tweeting about potential issues<\/a> with 2.16.0, with some <a href=\"https:\/\/issues.apache.org\/jira\/browse\/LOG4J2-3230\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">identifying the denial of service vulnerability<\/a>.&nbsp;<\/p>\n<section class=\"sharethrough-top placeholder\"> <\/section>\n<p>Discussion about Log4j has dominated conversation all week. CISA <a href=\"https:\/\/www.zdnet.com\/article\/cisa-orders-federal-agencies-to-mitigate-log4j-vulnerabilities-in-emergency-directive\/\" target=\"_blank\" rel=\"noopener\">released multiple advisories<\/a> mandating federal civilian agencies in the US <a href=\"https:\/\/www.zdnet.com\/article\/cisa-orders-federal-civilian-agencies-to-patch-log4j-vulnerability-by-december-24\/\" target=\"_blank\" rel=\"noopener\">apply patches before Christmas<\/a> while <a href=\"https:\/\/www.zdnet.com\/article\/vmware-patches-critical-non-log4j-flaw-as-ibm-cisco-release-log4j-fixes\/\" target=\"_blank\" rel=\"noopener\">several major tech companies<\/a> like IBM, Cisco and VMware have raced to address Log4j vulnerabilities in their products.&nbsp;<\/p>\n<p>Security company Blumira claims to have found a&nbsp;<a href=\"https:\/\/www.blumira.com\/analysis-log4shell-local-trigger\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">new Log4j attack vector<\/a>&nbsp;that can be exploited through the path of a listening server on a machine or local network, potentially putting an end to the assumption that the problem was limited to exposed vulnerable servers.<\/p>\n<p>Other cybersecurity firms have found that <a href=\"https:\/\/www.zdnet.com\/article\/conti-ransomware-attacking-vmware-vcenter-servers-through-log4j-vulnerability\/\" target=\"_blank\" rel=\"noopener\">major ransomware groups like Conti<\/a> are exploring ways to take advantage of the vulnerability.&nbsp;<\/p>\n<p>Google <a href=\"https:\/\/security.googleblog.com\/2021\/12\/understanding-impact-of-apache-log4j.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">released a security report<\/a> on Friday where Open Source Insights Team members James Wetter and Nicky Ringland said they found that 35,863 of the available Java artifacts from Maven Central depend on the affected Log4j code. This means that more than 8% of all packages on Maven Central have at least one version that is impacted by this vulnerability, the two explained.&nbsp;<\/p>\n<p>&#8220;The average ecosystem impact of advisories affecting Maven Central is 2%, with the median less than 0.1%,&#8221; Wetter and Ringland said.&nbsp;<\/p>\n<p>So far, nearly 5,000 artifacts have been patched, leaving more than 30,000 more. But the two noted that it will be difficult to address the issue because of how deep Log4j is embedded in some products.&nbsp;<\/p>\n<figure class=\"image image-large shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/\" class=\"lazy\" alt=\"visualization-13.png\" height=\"auto\" width=\"470\" data-original=\"https:\/\/www.zdnet.com\/a\/img\/resize\/fadc1c18261e90ec63ab1d8421b3035418f1e7a3\/2021\/12\/18\/f80187b9-0bd0-4d79-9bba-c555044f8771\/visualization-13.png?width=470&amp;fit=bounds&amp;auto=webp\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/fadc1c18261e90ec63ab1d8421b3035418f1e7a3\/2021\/12\/18\/f80187b9-0bd0-4d79-9bba-c555044f8771\/visualization-13.png?width=470&amp;fit=bounds&amp;auto=webp\" class alt=\"visualization-13.png\" height=\"auto\" width=\"470\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><span class=\"credit\"> Google <\/span><\/figcaption><\/figure>\n<p>&#8220;Most artifacts that depend on log4j do so indirectly. The deeper the vulnerability is in a dependency chain, the more steps are required for it to be fixed. For greater than 80% of the packages, the vulnerability is more than one level deep, with a majority affected five levels down (and some as many as nine levels down),&#8221; Wetter and Ringland wrote.<\/p>\n<p><strong>&#8220;<\/strong>These packages will require fixes throughout all parts of the tree, starting from the deepest dependencies first.&#8221;<\/p>\n<p>The two went on to say that after looking at all publicly disclosed critical advisories affecting Maven packages, they found less than half (48%) of the artifacts affected by a vulnerability have been fixed, meaning it may take years for the Log4j issue to be solved.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Apache Software Foundation published a new Log4j patch late on Friday after discovering issues with 2.16.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-44496","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-18T18:05:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability\",\"datePublished\":\"2021-12-18T18:05:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\"},\"wordCount\":631,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\",\"name\":\"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\",\"datePublished\":\"2021-12-18T18:05:07+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-12-18T18:05:07+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability","datePublished":"2021-12-18T18:05:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/"},"wordCount":631,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","url":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","name":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","datePublished":"2021-12-18T18:05:07+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#primaryimage","url":"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/","contentUrl":"https:\/\/www.zdnet.com\/article\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Apache releases new 2.17.0 patch for Log4j to solve denial of service vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=44496"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44496\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=44496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=44496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=44496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}