flawopen.com/Incidents/Log4Shell

Log4Shell: Der Tag, an dem das Schreiben von Logdateien zur Codeausführung führte

Critical — CVSS 10.0 CWE-917: Expression Language Injection Disclosed December 2021
Einfach erklärt (ELI5)

Ein Protokollant im Büro hat die einzige Aufgabe, Aussagen von Besuchern mitzuschreiben. Jemand entdeckt: Nennt ein Besucher einen bestimmten Befehl mit einer Adresse, legt der Protokollant den Stift nieder, läuft zur genannten Adresse, holt einen versiegelten Umschlag von einem Fremden ab und führt alle Befehle darin aus.

The lessons that actually transfer

FAQ

Was Log4j 1.x affected?

Log4j 1.x did not contain the message-lookup feature that caused CVE-2021-44228. However, 1.x reached end of life in 2015 and carries its own unpatched issues, so it is not a safe destination — the correct move is forward to a current 2.x release.

Were the mitigation flags a real fix?

Early guidance circulated several stopgaps, including setting formatMsgNoLookups. These reduced exposure but were incomplete in some configurations and versions. Upgrading was, and remains, the reliable answer.

Related reading

Quellen und offizielle Bulletins