A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?

  • FineCoatMummy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    13
    ·
    4 days ago

    Guys I might be stuck in a time loop. There’s a Log4j2 remote execution exploit. Toy Story is one of the highest grossing films of the year. Foldable phones are in the headlines. Serena and Venus are playing doubles in the US Open.

  • sik0fewl@piefed.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    The vulnerability affects log4j-api versions 2.11.0 through 2.26.1 and log4j-coreversions 2.8.0 through 2.26.1.

    Oh, good. I’m still on Log4j v1.