Debian Security Update DSA-5020 apache-log4j2 - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,955
Reaction score
80
Credits
-1,257
Chen Zhaojun of Alibaba Cloud Security Team discovered a critical security vulnerability in Apache Log4j, a popular Logging Framework for Java. JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From version 2.15.0, this behavior has been disabled by default.

Continue reading...
 


Follow Linux.org

Members online


Top