A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?
You must log in or register to comment.
“A new Log4j RCE vulnerability announced…”

Guys I might be stuck in a time loop. There’s a Log4j2 remote execution exploit. Toy Story is one of the highest grossing films of the year. Foldable phones are in the headlines. Serena and Venus are playing doubles in the US Open.
Log4j will be the vector the AI uses to take over everything
Why are we still using this garbage
The vulnerability affects
log4j-apiversions 2.11.0 through 2.26.1 andlog4j-coreversions 2.8.0 through 2.26.1.Oh, good. I’m still on Log4j v1.


