CVE-2021-44228
30ee0a75-de6b-48de-a9ad-21f444ed73ce · v1A vciy decision record, version 1 of 1. This page re-derives every hash below from the stored bytes each time it loads.
- Subject
- CVE-2021-44228
- Identity
- cve: CVE-2021-44228
- Verdict
- Mitigated
- Review by
- not set
- Rationale
- Upgraded log4j-core to 2.17.1 across every service during the December 2021 disclosure window. Kept here as vciy's own worked example: the record and the mitigation date line up, and the evidence below is what the index held at the moment this was recorded.
- Context note
- none recorded
- Decided by
- [email protected]
- Recorded
- 2026-09-12T00:20:47.247000000Z
- Under custody
- 19 days, since 2026-09-12
- This version's hash
- 9ad7752cebd9a6564dc7d4dc486d76ea48ed3b99d6ba3f93149ab6a520496477
- Links back to
- 0000000000000000000000000000000000000000000000000000000000000000 (genesis, no predecessor)
Evidence frozen at recording
What the vciy index held for CVE-2021-44228 when this version was recorded on 2026-09-12, frozen into it.
| Fact | Value as recorded | Source |
|---|---|---|
| Known exploited | Listed in CISA's Known Exploited Vulnerabilities catalogue, added 2021-12-10, remediation due 2021-12-24 | CISA KEV catalogue, release of 2026-08-17 |
| EPSS score | 0.99999, model v2026.06.15 | EPSS, release of 2026-06-15 |
| Weakness, per the CNA | CWE-502 Deserialization of Untrusted Data; CWE-400 Uncontrolled Resource Consumption; CWE-20 Improper Input Validation | CVE Program record, cvelistV5 release of 2026-09-04 |
| Weakness, per NVD | CWE-20; CWE-400; CWE-502; CWE-917 | NVD's analysis, load of 2026-09-04 |
| Severity, per NVD | 10 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | NVD's analysis, load of 2026-09-04 |
| Affected version ranges |
| NVD's analysis, load of 2026-09-04 |
| Fixed version | 2.3.1; 2.12.2; 2.15.0 | CVE Program record, cvelistV5 release of 2026-09-04 |
When this was recorded, the newest release the index held of each source was: CISA KEV catalogue, release of 2026-09-11; EPSS, release of 2026-09-10. A value dated earlier is the one the index still held at that moment.
- Snapshot id
- sha256:71b6a00f410ff00dcbf38af19432bf646f57dc201dde87b69c5ba3d7e6bd2165
These values are part of v1's canonical bytes, so they are covered by v1's hash in the chain below. Change one character and that hash no longer matches. The snapshot id is the SHA-256 of exactly these values, recomputed on this page load. This page shows the values as they were recorded. It does not fetch them again from their sources, so it does not tell you whether a source has changed since.
The whole chain
- v1 mint 9ad7752cebd9a6564dc7d4dc486d76ea48ed3b99d6ba3f93149ab6a520496477 2026-09-12T00:20:47.247000000Z
Check it yourself
Do not take this page's word for it. The verifier below shares no code with this service: it is a single file with no dependencies, written from the published canonical form rather than from our implementation, and both are downloadable here. Download the export with the first button below, then run these two lines in the same folder.
curl -sO https://app.vciy.com/r/verify-vdr-export.mjs node verify-vdr-export.mjs export.json
The vdr.v1 export The verifier The canonical form it was written from
What that check does and does not settle. It re-derives every hash from the bytes in the export and confirms every version links to its predecessor, so a changed character anywhere is caught and named. It cannot tell you the export came from this record: the document is internally consistent, not anchored to anything outside itself. The export names this page as its proof_url for exactly that reason. Compare the two.