Executive brief
Apache Log4j2 JNDI features do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Affected products
- Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1)
Timeline
- 2021-12-10: disclosed
- 2021-12-10: advisory