Log4Shell
Summary
Vulnerable code
public String index(@RequestHeader("X-Api-Version") String apiVersion) {
logger.info("Received a request for API version " + apiVersion);
return "Hello, world!";
}Payloads
Scanning
WAF Bypass
Exploitation
Environment variables exfiltration
Remote Command Execution
References
Last updated