Episode #849 Quiz
Log4j & Log4Shell
Date: 2021-12-14 | Length: 1.5 hrs | Episode page at twit.tv
About this episode
The episode explains Log4Shell, CVE-2021-44228, a CVSS 10.0 remote-code-execution flaw in Log4j 2’s JNDI lookup feature. Malicious strings in logged input trigger LDAP/DNS lookups, fetching attacker code or secrets. Mitigation requires upgrading to Log4j 2.15.0, disabling lookups, and testing exposure with benign probes.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.