flawopen.com/Incidentes/Log4Shell

Log4Shell: o dia em que gravar logs se tornou execução remota de código

Critical — CVSS 10.0 CWE-917: Expression Language Injection Disclosed December 2021
ELI5 (Explicado de Forma Simples)

Imagine um cartório onde o escrivão anota tudo o que os visitantes dizem. Alguém descobre que se falar uma frase mágica com um endereço, o escrivão larga a caneta, vai até o endereço, pega um envelope fechado com um desconhecido e executa todas as ordens de dentro. O escrivão nunca deveria executar nada, apenas anotar.

The lessons that actually transfer

FAQ

Was Log4j 1.x affected?

Log4j 1.x did not contain the message-lookup feature that caused CVE-2021-44228. However, 1.x reached end of life in 2015 and carries its own unpatched issues, so it is not a safe destination — the correct move is forward to a current 2.x release.

Were the mitigation flags a real fix?

Early guidance circulated several stopgaps, including setting formatMsgNoLookups. These reduced exposure but were incomplete in some configurations and versions. Upgrading was, and remains, the reliable answer.

Related reading

Fontes e comunicados oficiais