CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
In short
Apache Log4j2 allows attackers to execute arbitrary code by injecting malicious commands into log messages. If an application uses a vulnerable version of Log4j2 and logs user-controlled data, an attacker can trigger code execution from remote servers.
Technical detail
CVE-2021-44228 exploits unsafe JNDI (Java Naming and Directory Interface) lookups in Log4j2 versions 2.0-beta9 through 2.15.0 when message lookup substitution is enabled. An attacker controlling log message content can inject JNDI expressions that load and execute arbitrary code from attacker-controlled LDAP or RMI endpoints. This requires the application to log attacker-influenced data without sanitization.
Summary generated and translated by AI from the official description.
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache Log4j2public PoCs found — 428
githubgithub.com/fullhunt/log4j-scan★ 3426githubgithub.com/kozmer/log4j-shell-poc★ 1849githubgithub.com/christophetd/log4shell-vulnerable-app★ 1142githubgithub.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words★ 950githubgithub.com/logpresso/CVE-2021-44228-Scanner★ 862githubgithub.com/f0ng/log4j2burpscanner★ 844githubgithub.com/mergebase/log4j-detector★ 640githubgithub.com/corretto/hotpatch-for-apache-log4j2★ 497githubgithub.com/jas502n/Log4j2-CVE-2021-44228★ 469githubgithub.com/fox-it/log4j-finder★ 439githubgithub.com/0xInfection/LogMePwn★ 395githubgithub.com/Diverto/nse-log4shell★ 352githubgithub.com/CERTCC/CVE-2021-44228_scanner★ 349githubgithub.com/back2root/log4shell-rex★ 292githubgithub.com/rubo77/log4j_checker_beta★ 247githubgithub.com/NS-Sp4ce/Vm4J★ 209githubgithub.com/takito1812/log4j-detect★ 195githubgithub.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept★ 182githubgithub.com/alexandre-lavoie/python-log4rce★ 178githubgithub.com/puzzlepeaches/Log4jUnifi★ 168githubgithub.com/mubix/CVE-2021-44228-Log4Shell-Hashes★ 155githubgithub.com/BinaryDefense/log4j-honeypot-flask★ 151githubgithub.com/NorthwaveSecurity/log4jcheck★ 126githubgithub.com/boundaryx/cloudrasp-log4j2★ 125githubgithub.com/simonis/Log4jPatch★ 108githubgithub.com/Adikso/minecraft-log4j-honeypot★ 107githubgithub.com/puzzlepeaches/Log4jCenter★ 106githubgithub.com/0xDexter0us/Log4J-Scanner★ 102githubgithub.com/MalwareTech/Log4jTools★ 94githubgithub.com/thomaspatzke/Log4Pot★ 94githubgithub.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce★ 90githubgithub.com/alexbakker/log4shell-tools★ 86githubgithub.com/giterlizzi/nmap-log4shell★ 78githubgithub.com/LiveOverflow/log4shell★ 72githubgithub.com/cyberxml/log4j-poc★ 72githubgithub.com/nccgroup/log4j-jndi-be-gone★ 72githubgithub.com/bigsizeme/Log4j-check★ 70githubgithub.com/future-client/CVE-2021-44228★ 66githubgithub.com/lucab85/log4j-cve-2021-44228★ 57githubgithub.com/authomize/log4j-log4shell-affected★ 52githubgithub.com/CreeperHost/Log4jPatcher★ 49githubgithub.com/CodeShield-Security/Log4JShell-Bytecode-Detector★ 49githubgithub.com/redhuntlabs/Log4JHunt★ 46githubgithub.com/dtact/divd-2021-00038--log4j-scanner★ 46githubgithub.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs★ 45githubgithub.com/1lann/log4shelldetect★ 45githubgithub.com/stripe/log4j-remediation-tools★ 40githubgithub.com/HynekPetrak/log4shell-finder★ 39githubgithub.com/infiniroot/nginx-mitigate-log4shell★ 38githubgithub.com/Y0-kan/Log4jShell-Scan★ 38githubgithub.com/hackinghippo/log4shell_ioc_ips★ 37githubgithub.com/fireeye/CVE-2021-44228★ 37githubgithub.com/greymd/CVE-2021-44228★ 35githubgithub.com/darkarnium/Log4j-CVE-Detect★ 35githubgithub.com/sassoftware/loguccino★ 33githubgithub.com/Jeromeyoung/log4j2burpscanner★ 32githubgithub.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab★ 28githubgithub.com/qingtengyun/cve-2021-44228-qingteng-online-patch★ 25githubgithub.com/r3kind1e/Log4Shell-obfuscated-payloads-generator★ 25githubgithub.com/mufeedvh/log4jail★ 23githubgithub.com/toramanemre/log4j-rce-detect-waf-bypass★ 23githubgithub.com/pedrohavay/exploit-CVE-2021-44228★ 20githubgithub.com/Glease/Healer★ 19githubgithub.com/corelight/cve-2021-44228★ 19githubgithub.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell★ 18githubgithub.com/blake-fm/vcenter-log4j★ 17githubgithub.com/ab0x90/CVE-2021-44228_PoC★ 16githubgithub.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228★ 16githubgithub.com/lhotari/log4shell-mitigation-tester★ 16githubgithub.com/ossie-git/log4shell_sentinel★ 14githubgithub.com/mitiga/log4shell-cloud-scanner★ 14githubgithub.com/snow0715/log4j-Scan-Burpsuite★ 13githubgithub.com/zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service★ 13githubgithub.com/xsultan/log4jshield★ 13githubgithub.com/Nanitor/log4fix★ 12githubgithub.com/Hydragyrum/evil-rmi-server★ 12githubgithub.com/rakutentech/jndi-ldap-test-server★ 11githubgithub.com/claranet/ansible-role-log4shell★ 11githubgithub.com/thecyberneh/Log4j-RCE-Exploiter★ 11githubgithub.com/roxas-tan/CVE-2021-44228★ 10githubgithub.com/kubearmor/log4j-CVE-2021-44228★ 9githubgithub.com/qingtengyun/cve-2021-44228-qingteng-patch★ 9githubgithub.com/immunityinc/Log4j-JNDIServer★ 9githubgithub.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs★ 9githubgithub.com/obscuritylabs/log4shell-poc-lab★ 9githubgithub.com/wortell/log4j★ 9githubgithub.com/Tai-e/CVE-2021-44228★ 9githubgithub.com/DXC-StrikeForce/Burp-Log4j-HammerTime★ 8githubgithub.com/lfama/log4j_checker★ 8githubgithub.com/Labout/log4shell-rmi-poc★ 8githubgithub.com/atnetws/fail2ban-log4j★ 8githubgithub.com/cybersecurityworks553/log4j-shell-csw★ 8githubgithub.com/sunnyvale-it/CVE-2021-44228-PoC★ 8githubgithub.com/Azeemering/CVE-2021-44228-DFIR-Notes★ 7githubgithub.com/mschmnet/Log4Shell-demo★ 7githubgithub.com/OopsieWoopsie/mc-log4j-patcher★ 7githubgithub.com/0xsyr0/Log4Shell★ 7githubgithub.com/momos1337/Log4j-RCE★ 7githubgithub.com/marcourbano/CVE-2021-44228★ 7githubgithub.com/KosmX/CVE-2021-44228-example★ 7githubgithub.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit★ 7githubgithub.com/KeysAU/Get-log4j-Windows.ps1★ 7githubgithub.com/r00thunter/Log4Shell★ 7githubgithub.com/ssl/scan4log4j★ 6githubgithub.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228★ 6githubgithub.com/demining/Log4j-Vulnerability★ 6githubgithub.com/DragonSurvivalEU/RCE★ 6githubgithub.com/isuruwa/Log4j★ 6githubgithub.com/justakazh/Log4j-CVE-2021-44228★ 6githubgithub.com/AlexandreHeroux/Fix-CVE-2021-44228★ 6githubgithub.com/OlafHaalstra/log4jcheck★ 5githubgithub.com/snapattack/damn-vulnerable-log4j-app★ 5githubgithub.com/suuhm/log4shell4shell★ 5githubgithub.com/jacobtread/L4J-Vuln-Patch★ 5githubgithub.com/phoswald/sample-ldap-exploit★ 5githubgithub.com/many-fac3d-g0d/apache-tomcat-log4j★ 5githubgithub.com/mrlnstk/cve-2021-44228-minecraft-poc★ 5githubgithub.com/sud0x00/log4j-CVE-2021-44228★ 5githubgithub.com/winnpixie/log4noshell★ 5githubgithub.com/manuel-alvarez-alvarez/log4j-cve-2021-44228★ 5githubgithub.com/KeysAU/Get-log4j-Windows-local★ 5githubgithub.com/ankur-katiyar/log4j-docker★ 5githubgithub.com/shamo0/CVE-2021-44228★ 4githubgithub.com/inettgmbh/checkmk-log4j-scanner★ 4githubgithub.com/MrHarshvardhan/PY-Log4j-RCE-Scanner★ 4githubgithub.com/nkoneko/VictimApp★ 4githubgithub.com/corneacristian/Log4J-CVE-2021-44228-RCE★ 4githubgithub.com/Koupah/MC-Log4j-Patcher★ 4githubgithub.com/michaelsanford/Log4Shell-Honeypot★ 4githubgithub.com/yesspider-hacker/log4j-payload-generator★ 4githubgithub.com/Occamsec/log4j-checker★ 4githubgithub.com/M1ngGod/CVE-2021-44228-Log4j-lookup-Rce★ 4githubgithub.com/dbzoo/log4j_scanner★ 4githubgithub.com/ycdxsb/Log4Shell-CVE-2021-44228-ENV★ 4githubgithub.com/toramanemre/apache-solr-log4j-CVE-2021-44228★ 4githubgithub.com/sinakeshmiri/log4jScan★ 4githubgithub.com/Kr0ff/CVE-2021-44228★ 4githubgithub.com/zzzz0317/log4j2-vulnerable-spring-app★ 4githubgithub.com/lucab85/ansible-role-log4shell★ 4githubgithub.com/TheInterception/Log4J-Simulation-Tool★ 4githubgithub.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228★ 3githubgithub.com/threatmonit/Log4j-IOCs★ 3githubgithub.com/madCdan/JndiLookup★ 3githubgithub.com/vorburger/Log4j_CVE-2021-44228★ 3githubgithub.com/pmontesd/log4j-cve-2021-44228★ 3githubgithub.com/KirkDJohnson/Wireshark★ 3githubgithub.com/codiobert/log4j-scanner★ 3githubgithub.com/ubitech/cve-2021-44228-rce-poc★ 3githubgithub.com/zlepper/CVE-2021-44228-Test-Server★ 3githubgithub.com/mss/log4shell-hotfix-side-effect★ 3githubgithub.com/alexandreroman/cve-2021-44228-workaround-buildpack★ 3githubgithub.com/Joefreedy/Log4j-Windows-Scanner★ 3githubgithub.com/saharNooby/log4j-vulnerability-patcher-agent★ 3githubgithub.com/Sma-Das/Log4j-PoC★ 3githubgithub.com/tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment★ 3githubgithub.com/CrackerCat/CVE-2021-44228-Log4j-Payloads★ 3githubgithub.com/hotpotcookie/CVE-2021-44228-white-box★ 3githubgithub.com/badb33f/Apache-Log4j-POC★ 3githubgithub.com/unlimitedsola/log4j2-rce-poc★ 3githubgithub.com/anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228★ 2githubgithub.com/1in9e/Apache-Log4j2-RCE★ 2githubgithub.com/binganao/Log4j2-RCE★ 2githubgithub.com/byteboycn/CVE-2021-44228-Apache-Log4j-Rce★ 2githubgithub.com/b-abderrahmane/CVE-2021-44228-playground★ 2githubgithub.com/mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform★ 2githubgithub.com/jeffbryner/log4j-docker-vaccine★ 2githubgithub.com/mzlogin/CVE-2021-44228-Demo★ 2githubgithub.com/tasooshi/horrors-log4shell★ 2githubgithub.com/dotPY-hax/log4py★ 2githubgithub.com/ph0lk3r/anti-jndi★ 2githubgithub.com/thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832★ 2githubgithub.com/avwolferen/Sitecore.Solr-log4j-mitigation★ 2githubgithub.com/george-petrakis/log4j-scanner-CVE-2021-44228★ 2githubgithub.com/jeffli1024/log4j-rce-test★ 2githubgithub.com/taurusxin/CVE-2021-44228★ 2githubgithub.com/perryflynn/find-log4j★ 2githubgithub.com/alpacamybags118/log4j-cve-2021-44228-sample★ 2githubgithub.com/VinniMarcon/Log4j-Updater★ 2githubgithub.com/alenazi90/log4j★ 2githubgithub.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent★ 2githubgithub.com/korteke/log4shell-demo★ 2githubgithub.com/Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228★ 2githubgithub.com/spasam/log4j2-exploit★ 2githubgithub.com/julian911015/Log4j-Scanner-Exploit★ 2githubgithub.com/chandru-gunasekaran/log4j-fix-CVE-2021-44228★ 2githubgithub.com/BabooPan/Log4Shell-CVE-2021-44228-Demo★ 2githubgithub.com/Vulnmachines/log4jshell_CVE-2021-44228★ 2githubgithub.com/dcm2406/CVE-Lab★ 2githubgithub.com/lathika-3006/Solar-exploiting-log-4j★ 2githubgithub.com/mn-io/log4j-spring-vuln-poc★ 1githubgithub.com/JiuBanSec/Log4j-CVE-2021-44228★ 1githubgithub.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228★ 1githubgithub.com/pravin-pp/log4j2-CVE-2021-44228★ 1githubgithub.com/p3dr16k/log4j-1.2.15-mod★ 1githubgithub.com/chilliwebs/CVE-2021-44228_Example★ 1githubgithub.com/Apipia/log4j-pcap-activity★ 1githubgithub.com/dpomnean/log4j_scanner_wrapper★ 1githubgithub.com/gcmurphy/chk_log4j★ 1githubgithub.com/Woahd/log4j-urlscanner★ 1githubgithub.com/danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-★ 1githubgithub.com/kali-dass/CVE-2021-44228-log4Shell★ 1githubgithub.com/qw3rtyou/CVE-2021-44228_dockernize★ 1githubgithub.com/Panyaprach/Prove-CVE-2021-44228★ 1githubgithub.com/Carlos-Mesquita/TPASLog4ShellPoC★ 1githubgithub.com/Hoanle396/CVE-2021-44228-demo★ 1githubgithub.com/sec13b/CVE-2021-44228-POC★ 1githubgithub.com/trickyearlobe/inspec-log4j★ 1githubgithub.com/cado-security/log4shell★ 1githubgithub.com/RrUZi/Awesome-CVE-2021-44228★ 1githubgithub.com/DiCanio/CVE-2021-44228-docker-example★ 1githubgithub.com/Rk-000/Log4j_scan_Advance★ 1githubgithub.com/uint0/cve-2021-44228--spring-hibernate★ 1githubgithub.com/helsecert/CVE-2021-44228★ 1githubgithub.com/VerveIndustrialProtection/CVE-2021-44228-Log4j★ 1githubgithub.com/demonrvm/Log4ShellRemediation★ 1githubgithub.com/horrister/log4shell-cve-2021-44228★ 1githubgithub.com/pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC★ 1githubgithub.com/guerzon/log4shellpoc★ 1githubgithub.com/MarceloLeite2604/log4j-vulnerability★ 1githubgithub.com/sourcegraph/log4j-cve-code-search-resources★ 1githubgithub.com/andalik/log4j-filescan★ 1githubgithub.com/halibobor/log4j2★ 1githubgithub.com/srcporter/CVE-2021-44228★ 1githubgithub.com/Aschen/log4j-patched★ 1githubgithub.com/gyaansastra/CVE-2021-44228★ 1githubgithub.com/bcdunbar/CVE-2021-44228-poc★ 1githubgithub.com/rgl/log4j-log4shell-playground★ 1githubgithub.com/TPower2112/Writing-Sample-1★ 1githubgithub.com/nu11secur1ty/CVE-2021-44228-VULN-APP★ 1githubgithub.com/jaehnri/CVE-2021-44228★ 1githubgithub.com/kal1gh0st/MyLog4Shell★ 1githubgithub.com/kimobu/cve-2021-44228★ 1githubgithub.com/moshuum/tf-log4j-aws-poc★ 1githubgithub.com/Vulnmachines/log4j-cve-2021-44228★ 0githubgithub.com/kannthu/CVE-2021-44228-Apache-Log4j-Rce★ 0githubgithub.com/zhangxvx/Log4j-Rec-CVE-2021-44228★ 0githubgithub.com/wajda/log4shell-test-exploit★ 0githubgithub.com/LemonCraftRu/JndiRemover★ 0githubgithub.com/bhimsekhar/vulnerable-java-app★ 0githubgithub.com/Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE★ 0githubgithub.com/sysadmin0815/Fix-Log4j-PowershellScript★ 0githubgithub.com/RenYuH/log4j-lookups-vulnerability★ 0githubgithub.com/scheibling/py-log4shellscanner★ 0githubgithub.com/zaneef/CVE-2021-44228★ 0githubgithub.com/metodidavidovic/log4j-quick-scan★ 0githubgithub.com/WatchGuard-Threat-Lab/log4shell-iocs★ 0githubgithub.com/nikolas-charalambidis/cve-2021-44228★ 0githubgithub.com/m0rath/detect-log4j-exploitable★ 0githubgithub.com/datadavev/test-44228★ 0githubgithub.com/WYSIIWYG/Log4J_0day_RCE★ 0githubgithub.com/DANSI/PowerShell-Log4J-Scanner★ 0githubgithub.com/suniastar/scan-log4shell★ 0githubgithub.com/shivakumarjayaraman/log4jvulnerability-CVE-2021-44228★ 0githubgithub.com/j3kz/CVE-2021-44228-PoC★ 0githubgithub.com/axelcurmi/log4shell-docker-lab★ 0githubgithub.com/otaviokr/log4j-2021-vulnerability-study★ 0githubgithub.com/kkyehit/log4j_CVE-2021-44228★ 0githubgithub.com/leetxyz/CVE-2021-44228-Advisories★ 0githubgithub.com/gauthamg/log4j2021_vul_test★ 0githubgithub.com/TheArqsz/CVE-2021-44228-PoC★ 0githubgithub.com/TotallyNotAHaxxer/f-for-java★ 0githubgithub.com/bumheehan/cve-2021-44228-log4j-test★ 0githubgithub.com/racoon-rac/CVE-2021-44228★ 0githubgithub.com/hmxh123/Log4Shell-Vulnerability-Replication★ 0githubgithub.com/Codepumpking/log4shell-poc★ 0githubgithub.com/intel-xeon/CVE-2021-44228---detection-with-PowerShell★ 0githubgithub.com/limxuan/ehir-vuln-enterprise-login★ 0githubgithub.com/izzyacademy/log4shell-mitigation★ 0githubgithub.com/wheezysec/CVE-2021-44228-kusto★ 0githubgithub.com/xx-zhang/apache-log4j2-CVE-2021-44228★ 0githubgithub.com/r00thunter/Log4Shell-Scanner★ 0githubgithub.com/rejupillai/log4j2-hack-springboot★ 0githubgithub.com/DAADAISMYLIFE/log4shell-lab★ 0githubgithub.com/dbgee/CVE-2021-44228★ 0githubgithub.com/vutiendat323/CVE-2021-44228_Log4Shell★ 0githubgithub.com/ssl-user-en/Log4j-Scanner-Exploit★ 0githubgithub.com/BJLIYANLIANG/log4j-scanner★ 0githubgithub.com/grimch/log4j-CVE-2021-44228-workaround★ 0githubgithub.com/Toolsec/log4j-scan★ 0githubgithub.com/bsigouin/log4shell-vulnerable-app★ 0githubgithub.com/ToxicEnvelope/XSYS-Log4J2Shell-Ex★ 0githubgithub.com/felipe8398/ModSec-log4j2★ 0githubgithub.com/c3-h2/Log4j_Attacker_IPList★ 0githubgithub.com/mazhar-hassan/log4j-vulnerability★ 0githubgithub.com/xungzzz/VTI-IOCs-CVE-2021-44228★ 0githubgithub.com/s-retlaw/l4s_poc★ 0githubgithub.com/Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main★ 0githubgithub.com/LinkMJB/log4shell_scanner★ 0githubgithub.com/PoneyClairDeLune/LogJackFix★ 0githubgithub.com/romanutti/log4shell-vulnerable-app★ 0githubgithub.com/mklinkj/log4j2-test★ 0githubgithub.com/alexpena5635/CVE-2021-44228_scanner-main-Modified-★ 0githubgithub.com/aajuvonen/log4stdin★ 0githubgithub.com/IAmNewbieZ/CVE-2021-44228★ 0githubgithub.com/s-retlaw/l4srs★ 0githubgithub.com/Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228★ 0githubgithub.com/Phineas09/CVE-2021-44228★ 0githubgithub.com/yuuki1967/CVE-2021-44228-Apache-Log4j-Rce★ 0githubgithub.com/cbuschka/log4j2-rce-recap★ 0githubgithub.com/dark-ninja10/Log4j-CVE-2021-44228★ 0githubgithub.com/rodfer0x80/log4j2-prosecutor★ 0githubgithub.com/34zY/JNDI-Exploit-1.2-log4shell★ 0githubgithub.com/didoatanasov/cve-2021-44228★ 0githubgithub.com/ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228★ 0githubgithub.com/municipalparkingservices/CVE-2021-44228-Scanner★ 0githubgithub.com/tobiasoed/log4j-CVE-2021-44228★ 0githubgithub.com/kossatzd/log4j-CVE-2021-44228-test★ 0githubgithub.com/flxhaas/Scan-CVE-2021-44228★ 0githubgithub.com/VNYui/CVE-2021-44228★ 0githubgithub.com/1hakusai1/log4j-rce-CVE-2021-44228★ 0githubgithub.com/LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228★ 0githubgithub.com/lov3r/cve-2021-44228-log4j-exploits★ 0githubgithub.com/0xThiebaut/CVE-2021-44228★ 0githubgithub.com/Camphul/log4shell-spring-framework-research★ 0githubgithub.com/tuyenee/Log4shell★ 0githubgithub.com/jeremyrsellars/CVE-2021-44228_scanner★ 0githubgithub.com/sajanapamuditha/Cyber-Attack-Simulation-★ 0githubgithub.com/bhprin/log4j-vul★ 0githubgithub.com/avirahul007/CVE-2021-44228★ 0githubgithub.com/neilc1964techned/craready-test-java-vulns★ 0githubgithub.com/markuman/aws-log4j-mitigations★ 0githubgithub.com/jyotisahu98/logpresso-CVE-2021-44228-Scanner★ 0githubgithub.com/MeterianHQ/log4j-vuln-coverage-check★ 0githubgithub.com/maxant/log4j2-CVE-2021-44228★ 0githubgithub.com/honeynet/log4shell-data★ 0githubgithub.com/b1tm0n3r/CVE-2021-44228★ 0githubgithub.com/MAFO-sec/mi-laboratorio-log4shell★ 0githubgithub.com/fireflyingup/log4j-poc★ 0githubgithub.com/guardicode/CVE-2021-44228_IoCs★ 0githubgithub.com/felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-★ 0githubgithub.com/lohanichaten/log4j-cve-2021-44228★ 0githubgithub.com/urholaukkarinen/docker-log4shell★ 0githubgithub.com/rv4l3r3/log4v-vuln-check★ 0githubgithub.com/Crane-Mocker/log4j-poc★ 0githubgithub.com/uint0/cve-2021-44228-helpers★ 0githubgithub.com/jomjosh17/Log4Shell-CVE-2021-44228-★ 0githubgithub.com/recanavar/vuln_spring_log4j2★ 0githubgithub.com/creamIcec/CVE-2021-44228-Apache-Log4j-Rce__review★ 0githubgithub.com/lonecloud/CVE-2021-44228-Apache-Log4j★ 0githubgithub.com/axisops/CVE-2021-44228★ 0githubgithub.com/hozyx/log4shell★ 0githubgithub.com/andypitcher/Log4J_checker★ 0githubgithub.com/0xBlackash/CVE-2021-44228★ 0githubgithub.com/wmohamed2033/wmohamed2033.github.io★ 0githubgithub.com/Saru1718/THM---Solar-exploiting-Log-4j★ 0githubgithub.com/Lavanya2085/solar-exploiting-log4j★ 0githubgithub.com/jdormannn/SecureOps-Lab★ 0githubgithub.com/joaovicdev/EXPLOIT-CVE-2021-44228★ 0githubgithub.com/pinaraltinok/Log4Shell-Attack★ 0githubgithub.com/Contrast-Security-OSS/CVE-2021-44228★ 0githubgithub.com/snatalius/log4j2-CVE-2021-44228-poc-local★ 0githubgithub.com/chilit-nl/log4shell-example★ 0githubgithub.com/kaleth4/CVE-2021-44228★ 0githubgithub.com/tieupham267/log4shell-coraza★ 0githubgithub.com/sandarenu/log4j2-issue-check★ 0githubgithub.com/roticagas/CVE-2021-44228-Demo★ 0githubgithub.com/tica506/Siem-queries-for-CVE-2021-44228★ 0githubgithub.com/strawhatasif/log4j-test★ 0githubgithub.com/ben-smash/l4j-info★ 0githubgithub.com/yanghaoi/CVE-2021-44228_Log4Shell★ 0githubgithub.com/andrii-kovalenko-celonis/log4j-vulnerability-demo★ 0githubgithub.com/ra890927/Log4Shell-CVE-2021-44228-Demo★ 0githubgithub.com/vino-theva/CVE-2021-44228★ 0githubgithub.com/tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228★ 0githubgithub.com/eurogig/jankybank★ 0githubgithub.com/digital-dev/Log4j-CVE-2021-44228-Remediation★ 0githubgithub.com/ocastel/log4j-shell-poc★ 0githubgithub.com/sqsec/log4j2_CVE-2021-44228★ 0githubgithub.com/Sumitpathania03/LOG4J-CVE-2021-44228★ 0githubgithub.com/53buahapel/log4shell-vulnweb★ 0githubgithub.com/funcid/log4j-exploit-fork-bomb★ 0githubgithub.com/Muhammad-Ali007/Log4j_CVE-2021-44228★ 0githubgithub.com/roshanshibu/Odysseus★ 0githubgithub.com/LucasPDiniz/CVE-2021-44228★ 0githubgithub.com/felixslama/log4shell-minecraft-demo★ 0githubgithub.com/ShlomiRex/log4shell_lab★ 0githubgithub.com/scabench/l4j-tp1★ 0githubgithub.com/scabench/l4j-fp1★ 0githubgithub.com/KtokKawu/l4s-vulnapp★ 0githubgithub.com/agylabs/log4shell-remediation★ 0githubgithub.com/YangHyperData/LOGJ4_PocShell_CVE-2021-44228★ 0githubgithub.com/NikitaPark/Log4Shell-PoC-Application★ 0githubgithub.com/FacundoMfernandez/pentesting-obioba★ 0githubgithub.com/asd58584388/CVE-2021-44228★ 0githubgithub.com/OtisSymbos/CVE-2021-44228-Log4Shell-★ 0githubgithub.com/safeer-accuknox/log4j-shell-poc★ 0githubgithub.com/AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-★ 0githubgithub.com/Super-Binary/cve-2021-44228★ 0githubgithub.com/ZacharyZcR/CVE-2021-44228★ 0githubgithub.com/aaronm-sysdig/log4j-vuln-demo★ 0githubgithub.com/yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-★ 0githubgithub.com/tpdlshdmlrkfmcla/Log4shell★ 0githubgithub.com/timothyjxhn/DeliberatelyVulnerableWebApp★ 0githubgithub.com/khaidtraivch/CVE-2021-44228-Log4Shell-★ 0githubgithub.com/Fauzan-Aldi/Log4j-_Vulnerability★ 0githubgithub.com/SerpilRivas/log4shell-homework9★ 0githubgithub.com/x1ongsec/CVE-2021-44228-Log4j-JNDI★ 0githubgithub.com/fabioeletto/hka-seminar-log4shell★ 0githubgithub.com/cuijiung/log4j-CVE-2021-44228★ 0githubgithub.com/Sorrence/CVE-2021-44228★ 0githubgithub.com/moften/Log4Shell★ 0githubgithub.com/KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device★ 0githubgithub.com/arabindadora/log4shell★ 0githubgithub.com/Mintimate/log4j2-bugmaker★ 0githubgithub.com/mgueye3/Log4Shell★ 0githubgithub.com/PCMKUIT/CVE-2021-44228---Log4Shell-Analysis★ 0githubgithub.com/DrHaitham/Log4Shell-CVE-2021-44228★ 0githubgithub.com/Loliverte/Log4j-Vulnerability★ 0githubgithub.com/JoseMariaMicoli/Log4Shell-PoC★ 0cve_referencepacketstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlunverifiedcve_referencepacketstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlunverifiedcve_referencepacketstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlunverifiedcve_referencepacketstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlunverifiedexploitdbwww.exploit-db.com/exploits/50592unverifiedcve_referencepacketstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/51183unverifiedcve_referencepacketstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlunverifiedcve_referencepacketstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlunverifiedexploitdbwww.exploit-db.com/exploits/50590unverifiedcve_referencepacketstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlunverifiedcve_referencepacketstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlunverifiedcve_referencepacketstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlunverifiedcve_referencepacketstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlhttp://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlhttp://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlhttp://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlhttp://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html