twitter.com/GossiTheDog/st
The library has a lot more wrong with it than this RCE vulnerability. It does string interpolation on parameters rather than only the format strings and you'll still be able to leak arbitrary variables, etc. to logs even if they block the RCE vectors...
Quote Tweet
If you already upgraded code to use just released log4j-2.15.0-rc1, it's still vulnerable - you now need to apply log4j-2.15.0-rc2 as there was a bypass. They is no stable release which fixes yet.
Show this thread


