Vulnerability Detail Examples · Example 4 of 7 in Well-Known CVEs

Log4Shell, with CVSS v3.1 10.0, four CWEs, a CISA KEV entry with known ransomware use and an EPSS score of 0.99999.

Param
cve

Asks for CVE-2021-44228, the Apache Log4j2 JNDI lookup flaw.

What to Notice

  • metrics.cvss_metric_v31 has the maximum score, 10.0, with scope CHANGED.
  • weaknesses lists CWE-20, CWE-400, CWE-502 and CWE-917; enrichment.cwe adds each CWE's name and description and, where the CWE catalog has them, its OWASP Top 10 category and CAPEC patterns.
  • enrichment.epss_score.epss is 0.99999, and enrichment.cisa_kev.date_added is 2021-12-10, the day the CVE was published.
  • enrichment.cpe starts with Siemens firmware: the record lists the affected products of other vendors too, not only Log4j itself.

Request

What this example sends. Every parameter is documented on Detail; the exact request is in the code panel.

ParameterValue
cvequeryCVE-2021-44228

Reference updated