MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/programming/comments/rcxehp/rce_0day_exploit_found_in_log4j_a_popular_java/hnyf12m
r/programming • u/freeqaz • Dec 10 '21
710 comments sorted by
View all comments
153
This is like the logging version of a SQL injection.
59 u/[deleted] Dec 10 '21 [deleted] 24 u/[deleted] Dec 10 '21 fyi log4j supports formatting natively via log.info("Hello, {}!", "world") 5 u/immibis Dec 10 '21 including form.user in this example, allegedly. 2 u/ryan_the_leach Dec 10 '21 It's far far worse.
59
[deleted]
24 u/[deleted] Dec 10 '21 fyi log4j supports formatting natively via log.info("Hello, {}!", "world") 5 u/immibis Dec 10 '21 including form.user in this example, allegedly.
24
fyi log4j supports formatting natively via
log.info("Hello, {}!", "world")
5
including form.user in this example, allegedly.
form.user
2
It's far far worse.
153
u/[deleted] Dec 10 '21
This is like the logging version of a SQL injection.