A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely ...
Apache Log4j2における新たなリモートコード実行の脆弱性が、8月24日に開示されている。ただし、影響を受けるのは特定の構成に限られ、Log4Shell(CVE-2021-44228)ほど深刻なわけではない模様。
TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control ...