![]() |
|
good chemistry is complicated, and a little bit messy -LW |
|
PerlMonks |
Re: Log4Shell and Log::Log4perlby Perlbotics (Bishop) |
on Dec 24, 2021 at 18:51 UTC ( #11139874=note: print w/replies, xml ) | Need Help?? |
Although Java is not directly involved, I think it's noteworthy that Log::Log4perl offers code execution while reading configuration files. This might be an entry point for an attacker, although not as serious as Log4Shell since it requires access to the Log4perl configuration files while Log4Shell requires just lazy or no input validation.
Output:
This feature can be disabled (see FAQ) using:
In Section
Seekers of Perl Wisdom
|
|