Log4Jã¨ã¯ãApacheãéçºããJavaç¨ã®ãã®ã³ã°ã©ã¤ãã©ãªã Log4Jã«ã¯ãlookupã¨ããæ©è½ãå«ã¾ãã¦ããããã°åºåæã«ã©ã³ã¿ã¤ã ã«æ å ±ãåºåãããã¨ãã§ããã ä¾ã¨ãã¦ã${java:runtime}ã¨ããæååã¯ãJavaã®ãã¼ã¸ã§ã³æååã«ç½®æãããã ãã®ä¸ã§ããä»ååå ã«ãªã£ãã®ã¯ãJndi Lookupã§ããã Jndi Lookupã¯ããããã¯ã¼ã¯ä¸ããå¤ãåå¾ãç½®æãããã®ã§ããã 使ç¨ããã¨ãLDAPã®ãããªãã£ã¬ã¯ããªã¸ã¢ã¯ã»ã¹ãããããã³ã«ãçµç±ãã¦å¤é¨ãã¡ã¤ã«ã¸ã®ã¢ã¯ã»ã¹ãå®è¡ããããã¨ãå¯è½ã§ããã ãã®ããããããã¯ã¼ã¯ä¸ã«Javaã¯ã©ã¹ãã¡ã¤ã«ãé ç½®ããLDAPãµã¼ãã¼ãæ§ç¯ããURLãLookupã®æååã«å½ã¦ã¯ãéä¿¡ããã¨Java Runtimeã§ãã®ããã°ã©ã ãå®è¡ãããã CVE: CVE-2021-44228 JNDI Lookup
{{#tags}}- {{label}}
{{/tags}}