
12/10/2021 · John Graham-Cumming
What this post added
This post details the Log4j2 vulnerability (CVE-2021-44228), explaining its history, how it was introduced via the JNDILookup plugin in Log4j 2.0-beta9, and how it can be exploited through JNDI and LDAP. It provides mitigation techniques (upgrading Log4j or removing the JndiLookup class) and outlines Cloudflare's immediate response by rolling out firewall rules to block the 'jndi' Lookup in common HTTP request locations to protect customers.