New Log4j2 Deserialization Flaw Could Enable Remote Code Execution
programming.dev
New Log4j2 Deserialization Flaw Could Enable Remote Code Execution
cross-posted from: https://lemmy.world/post/51139325 [https://lemmy.world/post/51139325] > A newly reported flaw can bypass FilteredObjectInputStream protections through java.rmi.MarshalledObject, potentially enabling RCE and DoS in vulnerable environments. Could this become another major Log4j security headache?
0 comments
No comments yet.