A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?
New Log4j2 Deserialization Flaw Could Enable Remote Code Execution
https://thecybersecguru.com/news/log4j2-deserialization-vulnerability-rce/
5 Comments
mlfh@lm.mlfh.org · 19 pts · 20d
"A new Log4j RCE vulnerability announced..."
FineCoatMummy@sh.itjust.works · 14 pts · 19d
Guys I might be stuck in a time loop. There's a Log4j2 remote execution exploit. Toy Story is one of the highest grossing films of the year. Foldable phones are in the headlines. Serena and Venus are playing doubles in the US Open.
fake@sh.itjust.works · 5 pts · 19d
Log4j will be the vector the AI uses to take over everything
spacegoat@lemmy.world · 2 pts · 19d
Why are we still using this garbage
sik0fewl@piefed.ca · 1 pts · 19d
Oh, good. I’m still on Log4j v1.