Ariel Shaqed (Scolnicov)
12/10/2021, 7:36 PMAriel Shaqed (Scolnicov)
12/11/2021, 6:48 AMlog4j2.formatMsgNoLookups=true
.
This is CVE-2021-44228, and because it is driven by data it may be a very big deal.
I shall be producing a full analysis for whether our clients ever log user-supplied data by tomorrow: the clients do see object keys (paths) and may log or include them as errors, these are user-controlled and thus suspect. I shall also determine whether our JVM clients assemble log4jv2.
That said, at this point switching off this whole lookup mess as detailed in the above blog or CVE is the only safe course of action.Ariel Shaqed (Scolnicov)
12/12/2021, 10:14 AMlog4j2.formatMsgNoLookups=true
or use some other workaround.