This content originally appeared on DEV Community and was authored by Heddi Nabbisen
Log4j 2.17.1 was released because a new vulnerability on RCE (Remote Code Execution) had been found in 2.17.0. (CVE-2021-4483)
According to The Apache Software Founndation, CVSS is 6.6 and the severity is moderate.
There is the risk when an attacker has the permission to modify the logging configuration file.
This post is based on the tweet by my company.
This content originally appeared on DEV Community and was authored by Heddi Nabbisen
Heddi Nabbisen | Sciencx (2021-12-28T22:36:48+00:00) A new RCE vulnerability on Log4j 2.17.0 (CVE-2021-4483). Retrieved from https://www.scien.cx/2021/12/28/a-new-rce-vulnerability-on-log4j-2-17-0-cve-2021-4483/
Please log in to upload a file.
There are no updates yet.
Click the Upload button above to add an update.