漏洞描述
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
logging.apache.orghttps://logging.apache.org/log4j/2.x/security.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-44228↗github.comhttps://github.com/advisories/GHSA-jfh8-c2jp-5v3q↗www.lunasec.iohttps://www.lunasec.io/docs/blog/log4j-zero-day/↗gist.github.comhttps://gist.github.com/bugbountynights/dde69038573db1c12705edb39f9a704a↗