Apache Log4j Vulnerability Called Log4Shell Actively Exploited
released on 2021-12-14 @ 11:58:18 AM
A vulnerability in Apache Log4j, a widely used logging package for Java has been found. The vulnerability, which can allow an attacker to execute arbitrary code by sending crafted log messages, has been identified as CVE-2021-44228 and given the name Log4Shell. It was first reported privately to Apache on November 24 and was patched with version 2.15.0 of Log4j on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter. Trendmicro has developed a Log4j vulnerability tester, a web-based tool that can help identify vulnerable server applications.