Re: log4j trivial RCE (similar to ShellShock) - "Log4Shell" CVE-2021-44228
Mike
Royce,
toggle quoted messageShow quoted text
From what I've been seeing, only version 2.x seems to be vulnerable, and 1.x is not, however nothing seems to be certain about that. Have you seen any hard confirmation yet whether 1.x is vulnerable? Thanks, Mike
On Fri, 10 Dec 2021, Royce Williams wrote:
This one is developing quickly, so I'll push updates here as I discover them:
|
|