AiRolG · @airolgloria
15 followers · 406 posts · Server mastodon.online

a 0-day exploit in the popular Java logging library log4j was discovered that results in Remote Code Execution (RCE) by logging a certain string.
* the impact of the exploit (full server control)
* JDK versions greater than 6u211, 7u201, 8u191, and 11.0.1 are safe
* 2.0 <= Apache log4j <= 2.14.1 are in trouble


lunasec.io/docs/blog/log4j-zer

#update #jndi #rce #apache #p0rz9 #day2 #Java #log4j2

Last updated 4 years ago