CVE-2021-44228 (Log4Shell)¶
MITRE. (2021). CVE-2021-44228 (Log4Shell). Common Vulnerabilities and Exposures.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Inherited-Substrate Risk
- The latent origin condition is the JNDI-lookup feature, a design decision made by Log4j's authors years earlier, dormant and unflagged, that allowed a logged string to trigger a remote class load.
This sourceRecords the Apache Log4j JNDI-lookup remote-code-execution flaw triggered by attacker-controlled strings reaching a log call.
- The latent origin condition is the JNDI-lookup feature, a design decision made by Log4j's authors years earlier, dormant and unflagged, that allowed a logged string to trigger a remote class load.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:911f685386e9 · see in the full table