<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Roy van Rijn on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/roy-van-rijn/</link><description>Articles written by Roy van Rijn on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 15 Dec 2021 12:49:15 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/roy-van-rijn/index.xml" rel="self" type="application/rss+xml"/><item><title>Log4Shell / Leak4J</title><link>https://foojayio.github.io/website/today/log4shell-leak4j/</link><pubDate>Wed, 15 Dec 2021 12:49:15 +0000</pubDate><guid>https://foojayio.github.io/website/today/log4shell-leak4j/</guid><description>&lt;p&gt;Over the last couple of days (and nights) I&amp;rsquo;ve been studying the new (extremely dangerous) vulnerability in log4j2 called &lt;a href="https://en.wikipedia.org/wiki/Log4Shell" target="_blank" rel="noopener noreferrer"&gt;Log4Shell&lt;/a&gt;
).&lt;/p&gt;
&lt;p&gt;All versions of log4j-core from 2.0-beta9 to 2.14.1 are affected by this, and it&amp;rsquo;s a &lt;strong&gt;big&lt;/strong&gt; one.&lt;/p&gt;
&lt;p&gt;This vulnerability allows the attacker to remotely execute code on your system, with the ability to get complete control of the underlying servers.&lt;/p&gt;
&lt;p&gt;Log4J has, for a long time, been the most used logging framework in the Java landscape. It&amp;rsquo;s extremely widely used and this attack has the most broad trigger you can imagine: It needs to log something.&lt;/p&gt;</description></item></channel></rss>