3 ms·
From a quick look at the lunasec page, it looks we can mitigate by blocking outbound LDAP traffic to unknown destinations?
by janstice 5y ago
From a quick look at the lunasec page, it looks we can mitigate by blocking outbound LDAP traffic to unknown destinations?
- IiydAbITMvJkqKf 5y agoIf you want to go down the route, you should check if log4j allows a port to be specified in the LDAP URI. If it does, firewalling one port won't do anything.
- znep 5y agoYes, you can specify a port.
- jsavin 5y agoThe vulnerability affects any process with network-facing endpoints that log user-input data. It's not LDAP-specific.
- antocv 5y agoNot by blocking outbound ldap by port, because ldap://hurrdurr:443/Evil.class