New Log4j2 Deserialization Flaw Could Enable Remote Code Execution

https://thecybersecguru.com/news/log4j2-deserialization-vulnerability-rce/

A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?

25 points · 5 comments · view on lemmy.world

5 Comments

mlfh@lm.mlfh.org · 19 pts · 20d

"A new Log4j RCE vulnerability announced..."

FineCoatMummy@sh.itjust.works · 14 pts · 19d

Guys I might be stuck in a time loop. There's a Log4j2 remote execution exploit. Toy Story is one of the highest grossing films of the year. Foldable phones are in the headlines. Serena and Venus are playing doubles in the US Open.

fake@sh.itjust.works · 5 pts · 19d

Log4j will be the vector the AI uses to take over everything

spacegoat@lemmy.world · 2 pts · 19d

Why are we still using this garbage

sik0fewl@piefed.ca · 1 pts · 19d

The vulnerability affects log4j-api versions 2.11.0 through 2.26.1 and log4j-coreversions 2.8.0 through 2.26.1.

Oh, good. I’m still on Log4j v1.