Overview
CVE-2021-44228 let a logged string trigger a JNDI lookup, so any user input written to the log could load and execute remote code.\nLog4j sat inside countless Java applications, servers and cloud products, making the blast radius effectively the whole industry.\nExploitation began within hours of disclosure and scanners continue to find unpatched instances years later.
Indicators of Compromise
Signals that suggest this is present on a system.
- HTTP requests containing ${jndi:ldap://
- Log entries containing JNDI reference strings
- New class files appearing in application temp directories
Controls that stop it
-
Patch Promptly and Continuously
Maintain an inventory of every framework, plugin and library you run, subscribe to their advisories, and apply fixes on a defined SLA measured in days rather than months. Prioritise anything reachable from the internet or already exploited in the wild. Automate the process so patching does not depend on someone remembering to do it.