这是indexloc提供的服务,不要输入任何密码
Skip to content

[SECURITY] RCE 0-day in log4j - Conclusion: Lombok itself not affected #3063

@bauerpl

Description

@bauerpl

Describe the bug
In log4j library was discovered a 0-day exploit that results in Remote Code Execution (RCE) by logging a certain string. The vulnerability impacts Apache Log4j 2 versions 2.0 to 2.14.1.

Additional context
https://www.randori.com/blog/cve-2021-44228/

Expected behavior
Immediate update of log4j library to the latest version (right now it is 2.15.0 according to the changelog)

Jump to latest assesment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions