Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA, has a working public exploit and 2 threat group(s) use it.
ssvc Actcvss 10epss 100%
from disclosure to weapon0 days
Published on NVDDec 10
1st PoCJan 1
metasploitDec 9
CISA KEVDec 10
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 group(s)523 public exploit(s)
Who exploits it — 2
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Action required by CISAfederal deadline: 2021-12-24
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache Log4j2public PoCs found — 523
exploitdbwww.exploit-db.com/exploits/51183unverifiedexploitdbwww.exploit-db.com/exploits/50592unverifiedexploitdbwww.exploit-db.com/exploits/50590unverifiedgithubgithub.com/fullhunt/log4j-scan★ 3424githubgithub.com/kozmer/log4j-shell-poc★ 1851githubgithub.com/christophetd/log4shell-vulnerable-app★ 1139githubgithub.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words★ 950githubgithub.com/logpresso/CVE-2021-44228-Scanner★ 861githubgithub.com/f0ng/log4j2burpscanner★ 841githubgithub.com/mergebase/log4j-detector★ 640githubgithub.com/corretto/hotpatch-for-apache-log4j2★ 497githubgithub.com/jas502n/Log4j2-CVE-2021-44228★ 469githubgithub.com/fox-it/log4j-finder★ 439githubgithub.com/0xInfection/LogMePwn★ 395githubgithub.com/Diverto/nse-log4shell★ 352githubgithub.com/CERTCC/CVE-2021-44228_scanner★ 350githubgithub.com/back2root/log4shell-rex★ 291githubgithub.com/rubo77/log4j_checker_beta★ 247githubgithub.com/NS-Sp4ce/Vm4J★ 209githubgithub.com/takito1812/log4j-detect★ 195githubgithub.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept★ 182githubgithub.com/alexandre-lavoie/python-log4rce★ 178githubgithub.com/puzzlepeaches/Log4jUnifi★ 170githubgithub.com/mubix/CVE-2021-44228-Log4Shell-Hashes★ 155githubgithub.com/BinaryDefense/log4j-honeypot-flask★ 149githubgithub.com/NorthwaveSecurity/log4jcheck★ 126githubgithub.com/boundaryx/cloudrasp-log4j2★ 126githubgithub.com/simonis/Log4jPatch★ 108githubgithub.com/puzzlepeaches/Log4jCenter★ 106githubgithub.com/Adikso/minecraft-log4j-honeypot★ 106githubgithub.com/0xDexter0us/Log4J-Scanner★ 102githubgithub.com/thomaspatzke/Log4Pot★ 94githubgithub.com/MalwareTech/Log4jTools★ 94githubgithub.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce★ 89githubgithub.com/alexbakker/log4shell-tools★ 86githubgithub.com/giterlizzi/nmap-log4shell★ 78githubgithub.com/nccgroup/log4j-jndi-be-gone★ 72githubgithub.com/LiveOverflow/log4shell★ 72githubgithub.com/cyberxml/log4j-poc★ 72githubgithub.com/bigsizeme/Log4j-check★ 70githubgithub.com/future-client/CVE-2021-44228★ 66githubgithub.com/lucab85/log4j-cve-2021-44228★ 57githubgithub.com/authomize/log4j-log4shell-affected★ 52githubgithub.com/CreeperHost/Log4jPatcher★ 49githubgithub.com/CodeShield-Security/Log4JShell-Bytecode-Detector★ 49githubgithub.com/redhuntlabs/Log4JHunt★ 47githubgithub.com/dtact/divd-2021-00038--log4j-scanner★ 46githubgithub.com/1lann/log4shelldetect★ 45githubgithub.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs★ 44githubgithub.com/stripe/log4j-remediation-tools★ 40githubgithub.com/HynekPetrak/log4shell-finder★ 39githubgithub.com/infiniroot/nginx-mitigate-log4shell★ 38githubgithub.com/Y0-kan/Log4jShell-Scan★ 38githubgithub.com/fireeye/CVE-2021-44228★ 37githubgithub.com/hackinghippo/log4shell_ioc_ips★ 37githubgithub.com/darkarnium/Log4j-CVE-Detect★ 35githubgithub.com/greymd/CVE-2021-44228★ 35githubgithub.com/sassoftware/loguccino★ 33githubgithub.com/Jeromeyoung/log4j2burpscanner★ 32githubgithub.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab★ 27githubgithub.com/r3kind1e/Log4Shell-obfuscated-payloads-generator★ 25githubgithub.com/qingtengyun/cve-2021-44228-qingteng-online-patch★ 25githubgithub.com/toramanemre/log4j-rce-detect-waf-bypass★ 23githubgithub.com/mufeedvh/log4jail★ 22githubgithub.com/pedrohavay/exploit-CVE-2021-44228★ 20githubgithub.com/corelight/cve-2021-44228★ 19githubgithub.com/Glease/Healer★ 19githubgithub.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell★ 18githubgithub.com/blake-fm/vcenter-log4j★ 17githubgithub.com/ab0x90/CVE-2021-44228_PoC★ 16githubgithub.com/lhotari/log4shell-mitigation-tester★ 16githubgithub.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228★ 15githubgithub.com/mitiga/log4shell-cloud-scanner★ 14githubgithub.com/ossie-git/log4shell_sentinel★ 14githubgithub.com/snow0715/log4j-Scan-Burpsuite★ 13githubgithub.com/zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service★ 13githubgithub.com/xsultan/log4jshield★ 13githubgithub.com/Hydragyrum/evil-rmi-server★ 12githubgithub.com/Nanitor/log4fix★ 12githubgithub.com/claranet/ansible-role-log4shell★ 11githubgithub.com/thecyberneh/Log4j-RCE-Exploiter★ 11githubgithub.com/rakutentech/jndi-ldap-test-server★ 11githubgithub.com/roxas-tan/CVE-2021-44228★ 10githubgithub.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs★ 9githubgithub.com/immunityinc/Log4j-JNDIServer★ 9githubgithub.com/obscuritylabs/log4shell-poc-lab★ 9githubgithub.com/wortell/log4j★ 9githubgithub.com/kubearmor/log4j-CVE-2021-44228★ 9githubgithub.com/Tai-e/CVE-2021-44228★ 9githubgithub.com/qingtengyun/cve-2021-44228-qingteng-patch★ 9githubgithub.com/cybersecurityworks553/log4j-shell-csw★ 8githubgithub.com/lfama/log4j_checker★ 8githubgithub.com/DXC-StrikeForce/Burp-Log4j-HammerTime★ 8githubgithub.com/sunnyvale-it/CVE-2021-44228-PoC★ 8githubgithub.com/Labout/log4shell-rmi-poc★ 8githubgithub.com/atnetws/fail2ban-log4j★ 8githubgithub.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit★ 7githubgithub.com/r00thunter/Log4Shell★ 7githubgithub.com/marcourbano/CVE-2021-44228★ 7githubgithub.com/Azeemering/CVE-2021-44228-DFIR-Notes★ 7githubgithub.com/momos1337/Log4j-RCE★ 7githubgithub.com/KeysAU/Get-log4j-Windows.ps1★ 7githubgithub.com/KosmX/CVE-2021-44228-example★ 7githubgithub.com/mschmnet/Log4Shell-demo★ 7githubgithub.com/OopsieWoopsie/mc-log4j-patcher★ 7githubgithub.com/isuruwa/Log4j★ 6githubgithub.com/DragonSurvivalEU/RCE★ 6githubgithub.com/justakazh/Log4j-CVE-2021-44228★ 6githubgithub.com/ssl/scan4log4j★ 6githubgithub.com/demining/Log4j-Vulnerability★ 6githubgithub.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228★ 6githubgithub.com/0xsyr0/Log4Shell★ 6githubgithub.com/AlexandreHeroux/Fix-CVE-2021-44228★ 6githubgithub.com/OlafHaalstra/log4jcheck★ 5githubgithub.com/many-fac3d-g0d/apache-tomcat-log4j★ 5githubgithub.com/jacobtread/L4J-Vuln-Patch★ 5githubgithub.com/suuhm/log4shell4shell★ 5githubgithub.com/sud0x00/log4j-CVE-2021-44228★ 5githubgithub.com/mrlnstk/cve-2021-44228-minecraft-poc★ 5githubgithub.com/snapattack/damn-vulnerable-log4j-app★ 5githubgithub.com/manuel-alvarez-alvarez/log4j-cve-2021-44228★ 5githubgithub.com/winnpixie/log4noshell★ 5githubgithub.com/KeysAU/Get-log4j-Windows-local★ 5githubgithub.com/phoswald/sample-ldap-exploit★ 5githubgithub.com/ankur-katiyar/log4j-docker★ 5githubgithub.com/Koupah/MC-Log4j-Patcher★ 4githubgithub.com/zzzz0317/log4j2-vulnerable-spring-app★ 4githubgithub.com/nkoneko/VictimApp★ 4githubgithub.com/shamo0/CVE-2021-44228★ 4githubgithub.com/M1ngGod/CVE-2021-44228-Log4j-lookup-Rce★ 4githubgithub.com/TheInterception/Log4J-Simulation-Tool★ 4githubgithub.com/toramanemre/apache-solr-log4j-CVE-2021-44228★ 4githubgithub.com/MrHarshvardhan/PY-Log4j-RCE-Scanner★ 4githubgithub.com/michaelsanford/Log4Shell-Honeypot★ 4githubgithub.com/dbzoo/log4j_scanner★ 4githubgithub.com/Kr0ff/CVE-2021-44228★ 4githubgithub.com/sinakeshmiri/log4jScan★ 4githubgithub.com/Occamsec/log4j-checker★ 4githubgithub.com/inettgmbh/checkmk-log4j-scanner★ 4githubgithub.com/ycdxsb/Log4Shell-CVE-2021-44228-ENV★ 4githubgithub.com/lucab85/ansible-role-log4shell★ 4githubgithub.com/corneacristian/Log4J-CVE-2021-44228-RCE★ 4githubgithub.com/yesspider-hacker/log4j-payload-generator★ 4githubgithub.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228★ 3githubgithub.com/saharNooby/log4j-vulnerability-patcher-agent★ 3githubgithub.com/ubitech/cve-2021-44228-rce-poc★ 3githubgithub.com/vorburger/Log4j_CVE-2021-44228★ 3githubgithub.com/pmontesd/log4j-cve-2021-44228★ 3githubgithub.com/codiobert/log4j-scanner★ 3githubgithub.com/unlimitedsola/log4j2-rce-poc★ 3githubgithub.com/zlepper/CVE-2021-44228-Test-Server★ 3githubgithub.com/mss/log4shell-hotfix-side-effect★ 3githubgithub.com/tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment★ 3githubgithub.com/threatmonit/Log4j-IOCs★ 3githubgithub.com/CrackerCat/CVE-2021-44228-Log4j-Payloads★ 3githubgithub.com/madCdan/JndiLookup★ 3githubgithub.com/Joefreedy/Log4j-Windows-Scanner★ 3githubgithub.com/badb33f/Apache-Log4j-POC★ 3githubgithub.com/alexandreroman/cve-2021-44228-workaround-buildpack★ 3githubgithub.com/hotpotcookie/CVE-2021-44228-white-box★ 3githubgithub.com/Sma-Das/Log4j-PoC★ 3githubgithub.com/KirkDJohnson/Wireshark★ 3githubgithub.com/jeffli1024/log4j-rce-test★ 2githubgithub.com/byteboycn/CVE-2021-44228-Apache-Log4j-Rce★ 2githubgithub.com/thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832★ 2githubgithub.com/BabooPan/Log4Shell-CVE-2021-44228-Demo★ 2githubgithub.com/taurusxin/CVE-2021-44228★ 2githubgithub.com/dcm2406/CVE-Lab★ 2githubgithub.com/VinniMarcon/Log4j-Updater★ 2githubgithub.com/mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform★ 2githubgithub.com/korteke/log4shell-demo★ 2githubgithub.com/spasam/log4j2-exploit★ 2githubgithub.com/chandru-gunasekaran/log4j-fix-CVE-2021-44228★ 2githubgithub.com/perryflynn/find-log4j★ 2githubgithub.com/lathika-3006/Solar-exploiting-log-4j★ 2githubgithub.com/anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228★ 2githubgithub.com/1in9e/Apache-Log4j2-RCE★ 2githubgithub.com/dotPY-hax/log4py★ 2githubgithub.com/alpacamybags118/log4j-cve-2021-44228-sample★ 2githubgithub.com/avwolferen/Sitecore.Solr-log4j-mitigation★ 2githubgithub.com/ph0lk3r/anti-jndi★ 2githubgithub.com/alenazi90/log4j★ 2githubgithub.com/jeffbryner/log4j-docker-vaccine★ 2githubgithub.com/mzlogin/CVE-2021-44228-Demo★ 2githubgithub.com/julian911015/Log4j-Scanner-Exploit★ 2githubgithub.com/tasooshi/horrors-log4shell★ 2githubgithub.com/binganao/Log4j2-RCE★ 2githubgithub.com/b-abderrahmane/CVE-2021-44228-playground★ 2githubgithub.com/Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228★ 2githubgithub.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent★ 2githubgithub.com/george-petrakis/log4j-scanner-CVE-2021-44228★ 2githubgithub.com/Vulnmachines/log4jshell_CVE-2021-44228★ 2githubgithub.com/gyaansastra/CVE-2021-44228★ 1githubgithub.com/rgl/log4j-log4shell-playground★ 1githubgithub.com/VerveIndustrialProtection/CVE-2021-44228-Log4j★ 1githubgithub.com/dpomnean/log4j_scanner_wrapper★ 1githubgithub.com/uint0/cve-2021-44228--spring-hibernate★ 1githubgithub.com/andalik/log4j-filescan★ 1githubgithub.com/kal1gh0st/MyLog4Shell★ 1githubgithub.com/Apipia/log4j-pcap-activity★ 1githubgithub.com/TPower2112/Writing-Sample-1★ 1githubgithub.com/pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC★ 1githubgithub.com/demonrvm/Log4ShellRemediation★ 1githubgithub.com/sec13b/CVE-2021-44228-POC★ 1githubgithub.com/Hoanle396/CVE-2021-44228-demo★ 1githubgithub.com/cado-security/log4shell★ 1githubgithub.com/chilliwebs/CVE-2021-44228_Example★ 1githubgithub.com/DiCanio/CVE-2021-44228-docker-example★ 1githubgithub.com/RrUZi/Awesome-CVE-2021-44228★ 1githubgithub.com/kali-dass/CVE-2021-44228-log4Shell★ 1githubgithub.com/pravin-pp/log4j2-CVE-2021-44228★ 1githubgithub.com/Panyaprach/Prove-CVE-2021-44228★ 1githubgithub.com/kimobu/cve-2021-44228★ 1githubgithub.com/halibobor/log4j2★ 1githubgithub.com/sourcegraph/log4j-cve-code-search-resources★ 1githubgithub.com/helsecert/CVE-2021-44228★ 1githubgithub.com/JiuBanSec/Log4j-CVE-2021-44228★ 1githubgithub.com/p3dr16k/log4j-1.2.15-mod★ 1githubgithub.com/Woahd/log4j-urlscanner★ 1githubgithub.com/gcmurphy/chk_log4j★ 1githubgithub.com/guerzon/log4shellpoc★ 1githubgithub.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228★ 1githubgithub.com/Aschen/log4j-patched★ 1githubgithub.com/nu11secur1ty/CVE-2021-44228-VULN-APP★ 1githubgithub.com/trickyearlobe/inspec-log4j★ 1githubgithub.com/Rk-000/Log4j_scan_Advance★ 1githubgithub.com/mn-io/log4j-spring-vuln-poc★ 1githubgithub.com/briml3y/loguccino★ 1githubgithub.com/MarceloLeite2604/log4j-vulnerability★ 1githubgithub.com/moshuum/tf-log4j-aws-poc★ 1githubgithub.com/jaehnri/CVE-2021-44228★ 1githubgithub.com/bcdunbar/CVE-2021-44228-poc★ 1githubgithub.com/srcporter/CVE-2021-44228★ 1githubgithub.com/Carlos-Mesquita/TPASLog4ShellPoC★ 1githubgithub.com/qw3rtyou/CVE-2021-44228_dockernize★ 1githubgithub.com/danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-★ 1githubgithub.com/horrister/log4shell-cve-2021-44228★ 1githubgithub.com/Fauzan-Aldi/Log4j-_Vulnerability★ 0githubgithub.com/khaidtraivch/CVE-2021-44228-Log4Shell-★ 0githubgithub.com/0xThiebaut/CVE-2021-44228★ 0githubgithub.com/dbgee/CVE-2021-44228★ 0githubgithub.com/b1tm0n3r/CVE-2021-44228★ 0githubgithub.com/honeynet/log4shell-data★ 0githubgithub.com/MeterianHQ/log4j-vuln-coverage-check★ 0githubgithub.com/jomjosh17/Log4Shell-CVE-2021-44228-★ 0githubgithub.com/jyotisahu98/logpresso-CVE-2021-44228-Scanner★ 0githubgithub.com/avirahul007/CVE-2021-44228★ 0githubgithub.com/bhprin/log4j-vul★ 0githubgithub.com/jeremyrsellars/CVE-2021-44228_scanner★ 0githubgithub.com/wheezysec/CVE-2021-44228-kusto★ 0githubgithub.com/izzyacademy/log4shell-mitigation★ 0githubgithub.com/Kadantte/CVE-2021-44228-poc★ 0githubgithub.com/TheArqsz/CVE-2021-44228-PoC★ 0githubgithub.com/bhimsekhar/vulnerable-java-app★ 0githubgithub.com/nikolas-charalambidis/cve-2021-44228★ 0githubgithub.com/DANSI/PowerShell-Log4J-Scanner★ 0githubgithub.com/suniastar/scan-log4shell★ 0githubgithub.com/shivakumarjayaraman/log4jvulnerability-CVE-2021-44228★ 0githubgithub.com/j3kz/CVE-2021-44228-PoC★ 0githubgithub.com/kkyehit/log4j_CVE-2021-44228★ 0githubgithub.com/hmxh123/Log4Shell-Vulnerability-Replication★ 0githubgithub.com/limxuan/ehir-vuln-enterprise-login★ 0githubgithub.com/TotallyNotAHaxxer/f-for-java★ 0githubgithub.com/bumheehan/cve-2021-44228-log4j-test★ 0githubgithub.com/intel-xeon/CVE-2021-44228---detection-with-PowerShell★ 0githubgithub.com/xx-zhang/apache-log4j2-CVE-2021-44228★ 0githubgithub.com/r00thunter/Log4Shell-Scanner★ 0githubgithub.com/DAADAISMYLIFE/log4shell-lab★ 0githubgithub.com/rejupillai/log4j2-hack-springboot★ 0githubgithub.com/sydneysamantha/Triage-CVE-2021-44228-Log4Shell-Log4j-★ 0githubgithub.com/grimch/log4j-CVE-2021-44228-workaround★ 0githubgithub.com/Toolsec/log4j-scan★ 0githubgithub.com/c3-h2/Log4j_Attacker_IPList★ 0githubgithub.com/mazhar-hassan/log4j-vulnerability★ 0githubgithub.com/xungzzz/VTI-IOCs-CVE-2021-44228★ 0githubgithub.com/s-retlaw/l4s_poc★ 0githubgithub.com/PoneyClairDeLune/LogJackFix★ 0githubgithub.com/Ricardo354/homelab-CVE-2021-44228★ 0githubgithub.com/romanutti/log4shell-vulnerable-app★ 0githubgithub.com/mklinkj/log4j2-test★ 0githubgithub.com/alexpena5635/CVE-2021-44228_scanner-main-Modified-★ 0githubgithub.com/yuuki1967/CVE-2021-44228-Apache-Log4j-Rce★ 0githubgithub.com/AstralJays/TraditionalJay★ 0githubgithub.com/prmawyer/log4shell-vulnerable-app★ 0githubgithub.com/ra890927/Log4Shell-CVE-2021-44228-Demo★ 0githubgithub.com/vino-theva/CVE-2021-44228★ 0githubgithub.com/tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228★ 0githubgithub.com/eurogig/jankybank★ 0githubgithub.com/digital-dev/Log4j-CVE-2021-44228-Remediation★ 0githubgithub.com/ocastel/log4j-shell-poc★ 0githubgithub.com/arpitgupta369/log4shell-scanner★ 0githubgithub.com/razureink/cve-2021-44228-log4shell_rce_reproduction★ 0githubgithub.com/sqsec/log4j2_CVE-2021-44228★ 0githubgithub.com/ShlomiRex/log4shell_lab★ 0githubgithub.com/scabench/l4j-tp1★ 0githubgithub.com/scabench/l4j-fp1★ 0githubgithub.com/KtokKawu/l4s-vulnapp★ 0githubgithub.com/asd58584388/CVE-2021-44228★ 0githubgithub.com/OtisSymbos/CVE-2021-44228-Log4Shell-★ 0githubgithub.com/safeer-accuknox/log4j-shell-poc★ 0githubgithub.com/sfr0435122531-ui/-log4shell-lab★ 0githubgithub.com/AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-★ 0githubgithub.com/Super-Binary/cve-2021-44228★ 0githubgithub.com/ZacharyZcR/CVE-2021-44228★ 0githubgithub.com/yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-★ 0githubgithub.com/tpdlshdmlrkfmcla/Log4shell★ 0githubgithub.com/SerpilRivas/log4shell-homework9★ 0githubgithub.com/PCMKUIT/CVE-2021-44228---Log4Shell-Analysis★ 0githubgithub.com/DrHaitham/Log4Shell-CVE-2021-44228★ 0githubgithub.com/Loliverte/Log4j-Vulnerability★ 0githubgithub.com/JoseMariaMicoli/Log4Shell-PoC★ 0githubgithub.com/agylabs/log4shell-remediation★ 0githubgithub.com/Codepumpking/log4shell-poc★ 0githubgithub.com/wmohamed2033/wmohamed2033.github.io★ 0githubgithub.com/Saru1718/THM---Solar-exploiting-Log-4j★ 0githubgithub.com/cuijiung/log4j-CVE-2021-44228★ 0githubgithub.com/Sorrence/CVE-2021-44228★ 0githubgithub.com/moften/Log4Shell★ 0githubgithub.com/mgueye3/Log4Shell★ 0githubgithub.com/fabioeletto/hka-seminar-log4shell★ 0githubgithub.com/x1ongsec/CVE-2021-44228-Log4j-JNDI★ 0githubgithub.com/Crane-Mocker/log4j-poc★ 0githubgithub.com/uint0/cve-2021-44228-helpers★ 0githubgithub.com/Lavanya2085/solar-exploiting-log4j★ 0githubgithub.com/creamIcec/CVE-2021-44228-Apache-Log4j-Rce__review★ 0githubgithub.com/urholaukkarinen/docker-log4shell★ 0githubgithub.com/zhangxvx/Log4j-Rec-CVE-2021-44228★ 0githubgithub.com/LemonCraftRu/JndiRemover★ 0githubgithub.com/lohanichaten/log4j-cve-2021-44228★ 0githubgithub.com/datadavev/test-44228★ 0githubgithub.com/guardicode/CVE-2021-44228_IoCs★ 0githubgithub.com/fireflyingup/log4j-poc★ 0githubgithub.com/WYSIIWYG/Log4J_0day_RCE★ 0githubgithub.com/leetxyz/CVE-2021-44228-Advisories★ 0githubgithub.com/gauthamg/log4j2021_vul_test★ 0githubgithub.com/joaovicdev/EXPLOIT-CVE-2021-44228★ 0githubgithub.com/0xBlackash/CVE-2021-44228★ 0githubgithub.com/Mintimate/log4j2-bugmaker★ 0githubgithub.com/arabindadora/log4shell★ 0githubgithub.com/jdormannn/SecureOps-Lab★ 0githubgithub.com/KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device★ 0githubgithub.com/timothyjxhn/DeliberatelyVulnerableWebApp★ 0githubgithub.com/NikitaPark/Log4Shell-PoC-Application★ 0githubgithub.com/YangHyperData/LOGJ4_PocShell_CVE-2021-44228★ 0githubgithub.com/maxant/log4j2-CVE-2021-44228★ 0githubgithub.com/felixslama/log4shell-minecraft-demo★ 0githubgithub.com/pinaraltinok/Log4Shell-Attack★ 0githubgithub.com/LucasPDiniz/CVE-2021-44228★ 0githubgithub.com/roshanshibu/Odysseus★ 0githubgithub.com/Muhammad-Ali007/Log4j_CVE-2021-44228★ 0githubgithub.com/funcid/log4j-exploit-fork-bomb★ 0githubgithub.com/kaleth4/CVE-2021-44228★ 0githubgithub.com/tieupham267/log4shell-coraza★ 0githubgithub.com/53buahapel/log4shell-vulnweb★ 0githubgithub.com/sajanapamuditha/Cyber-Attack-Simulation-★ 0githubgithub.com/markuman/aws-log4j-mitigations★ 0githubgithub.com/tuyenee/Log4shell★ 0githubgithub.com/neilc1964techned/craready-test-java-vulns★ 0githubgithub.com/Sumitpathania03/LOG4J-CVE-2021-44228★ 0githubgithub.com/s-retlaw/l4srs★ 0githubgithub.com/Camphul/log4shell-spring-framework-research★ 0githubgithub.com/lov3r/cve-2021-44228-log4j-exploits★ 0githubgithub.com/IAmNewbieZ/CVE-2021-44228★ 0githubgithub.com/aajuvonen/log4stdin★ 0githubgithub.com/LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228★ 0githubgithub.com/felipe8398/ModSec-log4j2★ 0githubgithub.com/1hakusai1/log4j-rce-CVE-2021-44228★ 0githubgithub.com/ToxicEnvelope/XSYS-Log4J2Shell-Ex★ 0githubgithub.com/bsigouin/log4shell-vulnerable-app★ 0githubgithub.com/BJLIYANLIANG/log4j-scanner★ 0githubgithub.com/VNYui/CVE-2021-44228★ 0githubgithub.com/flxhaas/Scan-CVE-2021-44228★ 0githubgithub.com/ssl-user-en/Log4j-Scanner-Exploit★ 0githubgithub.com/otaviokr/log4j-2021-vulnerability-study★ 0githubgithub.com/axelcurmi/log4shell-docker-lab★ 0githubgithub.com/m0rath/detect-log4j-exploitable★ 0githubgithub.com/zaneef/CVE-2021-44228★ 0githubgithub.com/tobiasoed/log4j-CVE-2021-44228★ 0githubgithub.com/scheibling/py-log4shellscanner★ 0githubgithub.com/FacundoMfernandez/pentesting-obioba★ 0githubgithub.com/andypitcher/Log4J_checker★ 0githubgithub.com/hozyx/log4shell★ 0githubgithub.com/axisops/CVE-2021-44228★ 0githubgithub.com/rodfer0x80/log4j2-prosecutor★ 0githubgithub.com/yanghaoi/CVE-2021-44228_Log4Shell★ 0githubgithub.com/lonecloud/CVE-2021-44228-Apache-Log4j★ 0githubgithub.com/ben-smash/l4j-info★ 0githubgithub.com/strawhatasif/log4j-test★ 0githubgithub.com/recanavar/vuln_spring_log4j2★ 0githubgithub.com/tica506/Siem-queries-for-CVE-2021-44228★ 0githubgithub.com/chilit-nl/log4shell-example★ 0githubgithub.com/Contrast-Security-OSS/CVE-2021-44228★ 0githubgithub.com/snatalius/log4j2-CVE-2021-44228-poc-local★ 0githubgithub.com/kossatzd/log4j-CVE-2021-44228-test★ 0githubgithub.com/sandarenu/log4j2-issue-check★ 0githubgithub.com/roticagas/CVE-2021-44228-Demo★ 0githubgithub.com/vutiendat323/CVE-2021-44228_Log4Shell★ 0githubgithub.com/aaronm-sysdig/log4j-vuln-demo★ 0githubgithub.com/racoon-rac/CVE-2021-44228★ 0githubgithub.com/felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-★ 0githubgithub.com/Phineas09/CVE-2021-44228★ 0githubgithub.com/cbuschka/log4j2-rce-recap★ 0githubgithub.com/andrii-kovalenko-celonis/log4j-vulnerability-demo★ 0githubgithub.com/dark-ninja10/Log4j-CVE-2021-44228★ 0githubgithub.com/Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228★ 0githubgithub.com/34zY/JNDI-Exploit-1.2-log4shell★ 0githubgithub.com/didoatanasov/cve-2021-44228★ 0githubgithub.com/ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228★ 0githubgithub.com/LinkMJB/log4shell_scanner★ 0githubgithub.com/municipalparkingservices/CVE-2021-44228-Scanner★ 0githubgithub.com/Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main★ 0githubgithub.com/WatchGuard-Threat-Lab/log4shell-iocs★ 0githubgithub.com/metodidavidovic/log4j-quick-scan★ 0githubgithub.com/MAFO-sec/mi-laboratorio-log4shell★ 0githubgithub.com/RenYuH/log4j-lookups-vulnerability★ 0githubgithub.com/sysadmin0815/Fix-Log4j-PowershellScript★ 0githubgithub.com/Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE★ 0githubgithub.com/kannthu/CVE-2021-44228-Apache-Log4j-Rce★ 0githubgithub.com/wajda/log4shell-test-exploit★ 0githubgithub.com/Vulnmachines/log4j-cve-2021-44228★ 0githubgithub.com/rv4l3r3/log4v-vuln-check★ 0vulncheckvulncheck.com/xdb/d3b4139ec745unverifiedvulncheckvulncheck.com/xdb/620853d6da36unverifiedvulncheckvulncheck.com/xdb/2ae20daa876funverifiedvulncheckvulncheck.com/xdb/97d627f4b9baunverifiedvulncheckvulncheck.com/xdb/97fe40642663unverifiedvulncheckvulncheck.com/xdb/a19435132a43unverifiedvulncheckvulncheck.com/xdb/ba3e7e5b416cunverifiedvulncheckvulncheck.com/xdb/9516d10f9dc1unverifiedvulncheckvulncheck.com/xdb/1f35dbf46c65unverifiedvulncheckvulncheck.com/xdb/3a9ab83bcad0unverifiedvulncheckvulncheck.com/xdb/591512073cfaunverifiedvulncheckvulncheck.com/xdb/c057d8038a5aunverifiedvulncheckvulncheck.com/xdb/193cf7c8c810unverifiedvulncheckvulncheck.com/xdb/c555ac264c6eunverifiedvulncheckvulncheck.com/xdb/78f6e0136a54unverifiedvulncheckvulncheck.com/xdb/fb07ce8d99afunverifiedvulncheckvulncheck.com/xdb/f161ac09099funverifiedvulncheckvulncheck.com/xdb/54a722d3152aunverifiedvulncheckvulncheck.com/xdb/bc6bb6bf5116unverifiedvulncheckvulncheck.com/xdb/a57024d99795unverifiedvulncheckvulncheck.com/xdb/88e63ac32997unverifiedvulncheckvulncheck.com/xdb/c29640a5f3ebunverifiedvulncheckvulncheck.com/xdb/d33dca9d017bunverifiedvulncheckvulncheck.com/xdb/bb0d040b4903unverifiedvulncheckvulncheck.com/xdb/60c07310e663unverifiedvulncheckvulncheck.com/xdb/a6af622ffa8bunverifiedvulncheckvulncheck.com/xdb/77ee0efab407unverifiedvulncheckvulncheck.com/xdb/56c1c3c26112unverifiedvulncheckvulncheck.com/xdb/c0e60d5638edunverifiedvulncheckvulncheck.com/xdb/979783a8957bunverifiedvulncheckvulncheck.com/xdb/dba45441fe51unverifiedvulncheckvulncheck.com/xdb/c9cb2e8864a3unverifiedvulncheckvulncheck.com/xdb/2da304372505unverifiedvulncheckvulncheck.com/xdb/d8f0374c0fb9unverifiedvulncheckvulncheck.com/xdb/3d55c6b2d5fbunverifiedvulncheckvulncheck.com/xdb/4620cd5b1d60unverifiedvulncheckvulncheck.com/xdb/586ef33d6a3aunverifiedvulncheckvulncheck.com/xdb/21a43cd9e827unverifiedvulncheckvulncheck.com/xdb/e422a6a41204unverifiedvulncheckvulncheck.com/xdb/b79e30922575unverifiedvulncheckvulncheck.com/xdb/16f87a128c56unverifiedvulncheckvulncheck.com/xdb/a9fd7962edc9unverifiedvulncheckvulncheck.com/xdb/2b61358e6ec7unverifiedvulncheckvulncheck.com/xdb/4039d0278bc3unverifiedvulncheckvulncheck.com/xdb/fed04c94a2dcunverifiedvulncheckvulncheck.com/xdb/89e9c315c36aunverifiedvulncheckvulncheck.com/xdb/5cf83af550feunverifiedvulncheckvulncheck.com/xdb/841758b2d4f4unverifiedvulncheckvulncheck.com/xdb/067762c45d29unverifiedvulncheckvulncheck.com/xdb/1f6ed84ff8ceunverifiedvulncheckvulncheck.com/xdb/94dd05cb788bunverifiedvulncheckvulncheck.com/xdb/3b6093e72b93unverifiedvulncheckvulncheck.com/xdb/03e32dfe2489unverifiedvulncheckvulncheck.com/xdb/cda9cebcfb20unverifiedvulncheckvulncheck.com/xdb/33d1b4584ee8unverifiedvulncheckvulncheck.com/xdb/c2e335ff1a21unverifiedvulncheckvulncheck.com/xdb/a0ead52c9280unverifiedvulncheckvulncheck.com/xdb/b95e4a6239cbunverifiedvulncheckvulncheck.com/xdb/5dbed1320f90unverifiedcve_referencepacketstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlunverifiedcve_referencepacketstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlunverifiedcve_referencepacketstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlunverifiedcve_referencepacketstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlunverifiedcve_referencepacketstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlunverifiedcve_referencepacketstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlunverifiedcve_referencepacketstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlunverifiedcve_referencepacketstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlunverifiedcve_referencepacketstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlunverifiedcve_referencepacketstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/ee8034010d52unverifiedvulncheckvulncheck.com/xdb/a29851f816e5unverifiedvulncheckvulncheck.com/xdb/2ec648d04bb0unverifiedvulncheckvulncheck.com/xdb/b5a96a5bab4funverifiedvulncheckvulncheck.com/xdb/0746a8f83636unverifiedvulncheckvulncheck.com/xdb/d561b6e6d466unverifiedvulncheckvulncheck.com/xdb/7527d4f5f2a0unverifiedvulncheckvulncheck.com/xdb/5c6c4e68c806unverifiedvulncheckvulncheck.com/xdb/acf764964e3dunverifiedvulncheckvulncheck.com/xdb/add0ba7f7c25unverifiedvulncheckvulncheck.com/xdb/613b89e18d15unverifiedvulncheckvulncheck.com/xdb/7efaf1d3a217unverifiedvulncheckvulncheck.com/xdb/f09e3ee6088dunverifiedvulncheckvulncheck.com/xdb/d8fa91bbd26cunverifiedvulncheckvulncheck.com/xdb/7d9d51922da4unverifiedvulncheckvulncheck.com/xdb/8f5167ba3cc3unverifiedvulncheckvulncheck.com/xdb/8e035e285cf8unverifiedvulncheckvulncheck.com/xdb/1f9ebf288986unverifiedvulncheckvulncheck.com/xdb/f57f14ebef6cunverifiedvulncheckvulncheck.com/xdb/891de99c4645unverifiedvulncheckvulncheck.com/xdb/c63aff84cb37unverifiedvulncheckvulncheck.com/xdb/3c41edcbcaf2unverifiedvulncheckvulncheck.com/xdb/fe2d186d8c18unverifiedvulncheckvulncheck.com/xdb/326e6538c620unverifiedvulncheckvulncheck.com/xdb/e34e1d116791unverifiedvulncheckvulncheck.com/xdb/a313ecfd69acunverifiedvulncheckvulncheck.com/xdb/d372d3b26376unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlhttp://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlhttp://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlhttp://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlhttp://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html