代码审计-log4j2_rce分析

阅读: 评论:0

2024年2月6日发(作者:)

代码审计-log4j2_rce分析

exec:485, Runtime ():-1, ExploitgJlWqLWBF3newInstance0:-1, NativeConstructorAccessorImpl (t)newInstance:62, NativeConstructorAccessorImpl (t)newInstance:45, DelegatingConstructorAccessorImpl (t)newInstance:423, Constructor (t)newInstance:442, Class ()getObjectFactoryFromReference:163, NamingManager ()getObjectInstance:189, DirectoryManager ()

c_lookup:1085, LdapCtx ()p_lookup:542, ComponentContext ()lookup:177, PartialCompositeContext ()lookup:205, GenericURLContext ()lookup:94, ldapURLContext ()lookup:417, InitialContext ()lookup:172, JndiManager ()lookup:56, JndiLookup ()lookup:221, Interpolator ()resolveVariable:1110, StrSubstitutor ()substitute:1033, StrSubstitutor ()substitute:912, StrSubstitutor ()replace:467, StrSubstitutor ()format:132, MessagePatternConverter (n)format:38, PatternFormatter (n)toSerializable:344, PatternLayout$PatternSerializer ()toText:244, PatternLayout ()encode:229, PatternLayout ()encode:59, PatternLayout ()directEncodeEvent:197, AbstractOutputStreamAppender (er)tryAppend:190, AbstractOutputStreamAppender (er)append:181, AbstractOutputStreamAppender (er)tryCallAppender:156, AppenderControl ()callAppender0:129, AppenderControl ()callAppenderPreventRecursion:120, AppenderControl ()callAppender:84, AppenderControl ()callAppenders:540, LoggerConfig ()processLogEvent:498, LoggerConfig ()log:481, LoggerConfig ()log:456, LoggerConfig ()log:63, DefaultReliabilityStrategy ()log:161, Logger ()tryLogMessage:2205, AbstractLogger ()logMessageTrackRecursion:2159, AbstractLogger ()

结果,绕过成功7、2.15.0-rc2修复Handle URI exception Commit从github上提交的代码,可以看出给catch没有return null的问题修复了暂时还没有好的绕过思路,所以先这样吧

影响范围srping-boot-strater-log4j2Apache SolrApache FlinkApache

代码审计-log4j2_rce分析

本文发布于:2024-02-06 23:38:44,感谢您对本站的认可!

本文链接:https://www.4u4v.net/it/170723392562813.html

版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。

标签:没有   代码   绕过   范围   修复   影响   思路   看出
留言与评论(共有 0 条评论)
   
验证码:
排行榜

Copyright ©2019-2022 Comsenz Inc.Powered by ©

网站地图1 网站地图2 网站地图3 网站地图4 网站地图5 网站地图6 网站地图7 网站地图8 网站地图9 网站地图10 网站地图11 网站地图12 网站地图13 网站地图14 网站地图15 网站地图16 网站地图17 网站地图18 网站地图19 网站地图20 网站地图21 网站地图22/a> 网站地图23