4 ms·
No, you are still vulnerable, even with just what we know today and we're still finding more ways to break this library. 1. Attackers can still load code in yo
by staticassertion 5y ago
No, you are still vulnerable, even with just what we know today and we're still finding more ways to break this library.
1. Attackers can still load code in your class path.
2. Attackers can steal environment variables, VM information, system information, etc.
3. The issue isn't specific to LDAP in any way, that was just a particularly brutal way to exploit this vulnerability. There are other ways to achieve RCE.
We may find even more ways to attack this in the future. It is absolutely not a good idea to assume you're safe right now - if you have log4j in your dependency tree, you should keep a close eye on the discourse as it evolves.
edit: I'll just say that I think it's really premature to tell anyone that they're safe.
- layer8 5y agoAs far as log4j is concerned, the substitutions ("lookups" — this includes your #2) are now disabled by default, and can only be enabled by an attacker if he already has access to the application. I’m not sure what you’re referring to in #1 and #3, given that fix.