Apache Log4j2最新披露的一个问题可使攻击者在特定部署环境中绕过反序列化允许列表,实现远程代码执行。 该问题编号为Log4j2 #4255,影响通过网络可达的Java反序列化路径接收序列化Log4j事件的应用。
A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely in narrowly defined deployments.
A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results