2021å¹´12æ10æ¥ãããããJavaãã¼ã¹ã®ãªã¼ãã³ã½ã¼ã¹ã®ãã®ã³ã°ã©ã¤ãã©ãªã®Apache Log4jã«é¢ãã¦è¤æ°ã®èå¼±æ§ãå ±åããã¦ããã¾ããJPCERT/CCã§ãæ¬ä»¶ã«ã¤ãã¦ã注æåèµ·ãçºè¡ããé©å®æ´æ°ãè¡ã£ã¦ããã¾ãã æ¬è¨äºã§ã¯ã2022å¹´1æ5æ¥æç¹ã§ã®Apache Log4jã«é¢ããèå¼±æ§ã®ç¶æ³ãã¾ã¨ãã¦ãã¾ãã 注æåèµ·ã®å 容ã¨ãããã¦ãèªçµç¹ã§ã®Apache Log4jã¸ã®å¯¾å¿ç¶æ³ã®ç¢ºèªã®åèã«ãã¦ããã ããã¨å¹¸ãã§ãã 1) ç¾å¨å ¬è¡¨ããã¦ããèå¼±æ§ CVE-2021-44228 æ¦è¦ Apache Log4jã®Java Naming and Directory Interfaceï¼JNDIï¼æ©è½ã«é¢ããä»»æã®ã³ã¼ãå®è¡ã®èå¼±æ§ é éã®ç¬¬ä¸è ãç´°å·¥ããæååãéä¿¡ããLog4jããã°ã¨ãã¦è¨é²ãããã¨ã§ä»»æã®ã³ã¼ããå®è¡ããå¯è½æ§ããã å½±é¿ãã¼ã¸ã§ã³ Apache
{{#tags}}- {{label}}
{{/tags}}