[ https://issues.apache.org/jira/browse/LOG4J2-3221?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17459349#comment-17459349 ]
Lucy Menon commented on LOG4J2-3221: ------------------------------------ Hi [~rpopma], thank you for investigating and releasing the new CVE! I noticed that the new CVE shared on the [d...@logging.apache.org|mailto:d...@logging.apache.org] mailing list only mentions that this vector provides DOS in log4j 2.15.0 - there is no documentation that it allows the exploitation of CVE-2021-44228 in <2.15.0 in some environments even when the recommended mitigation of applying log4j2.formatMsgNoLookups=true is applied. I just wanted to point this out in case the recommended mitigation for CVE-2021-44228 should be amended to specify this. > JNDI lookups in layout (not message patterns) enabled in Log4j2 < 2.16.0 > ------------------------------------------------------------------------ > > Key: LOG4J2-3221 > URL: https://issues.apache.org/jira/browse/LOG4J2-3221 > Project: Log4j 2 > Issue Type: Bug > Reporter: Lucy Menon > Priority: Major > Fix For: 2.16.0 > > > The mitigation advice for CVE-2021-4428 suggests that for Log4j > 2.10.0 and > < 2.15.0, the vulnerability can be avoided by setting > -{{{}Dlog4j2.formatMsgNoLookups=true{}}} or upgrading to 2.15.0. However, > many users may not be aware that even in this case, lookups used in layouts > to provide specific pieces of context information will still recursively > resolve, possibly triggering JNDI lookups. In order to avoid > attacker-controlled JNDI lookups, users must also either: > * Ensure that no such lookups resolve to attacker-provided data > * Ensure that the the JndiLookup class is not loaded > * Upgrade to log4j2 2.16.0 (untested) -- This message was sent by Atlassian Jira (v8.20.1#820001)