Details
-
Improvement
-
Status: Triage Needed
-
P1
-
Resolution: Fixed
-
2.34.0
-
None
Description
-
- Overview
2.0 <= Apache log4j2 <= 2.14.1 has vulnerability.
> In most cases, developers may write error messages caused by user input into the log. Attackers can use this feature to construct special data request packets through this vulnerability, and ultimately trigger remote code execution.
[UPDATED]
The vulnerability is labeled to `CVE-2021-44228`.
-
- References
Attachments
Issue Links
- links to
(9 links to)