A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely in narrowly defined deployments. The issue, tracked as Log4j2 #4255, affects applications that accept serialized Log4j events through a network-accessible Java deserialization path. The reported weakness involves Log4j’s FilteredObjectInputStream, a utility designed to restrict which Java classes […]
Read the original article: