A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?

  • sik0fewl@piefed.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 days ago

    The vulnerability affects log4j-api versions 2.11.0 through 2.26.1 and log4j-coreversions 2.8.0 through 2.26.1.

    Oh, good. I’m still on Log4j v1.