flawopen.com/インシデント/Log4Shell

Log4Shell:ログファイルへの出力がリモートコード実行へと変貌した日

Critical — CVSS 10.0 CWE-917: Expression Language Injection Disclosed December 2021
わかりやすく解説 (ELI5)

来客の発言をノートに書き留めるだけの受付係を想像してください。ある日、客が特定のアドレスを含む合言葉を話すと、受付係が記録を中断し、その住所へ向かって見知らぬ人から手紙を受け取り、中の指示をすべて実行してしまうことが判明しました。受付係は記録するだけで、命令を実行してはならなかったのです。

The lessons that actually transfer

FAQ

Was Log4j 1.x affected?

Log4j 1.x did not contain the message-lookup feature that caused CVE-2021-44228. However, 1.x reached end of life in 2015 and carries its own unpatched issues, so it is not a safe destination — the correct move is forward to a current 2.x release.

Were the mitigation flags a real fix?

Early guidance circulated several stopgaps, including setting formatMsgNoLookups. These reduced exposure but were incomplete in some configurations and versions. Upgrading was, and remains, the reliable answer.

Related reading

情報源および公式アドバイザリ