Source |
The Hacker News |
Identifiant |
3821664 |
Date de publication |
2021-12-18 04:26:36 (vue: 2021-12-18 13:06:10) |
Titre |
New Local Attack Vector Expands the Attack Surface of Log4j Vulnerability |
Texte |
Cybersecurity researchers have discovered an entirely new attack vector that enables adversaries to exploit the Log4Shell vulnerability on servers locally by using a JavaScript WebSocket connection.
"This newly-discovered attack vector means that anyone with a vulnerable Log4j version on their machine or local private network can browse a website and potentially trigger the vulnerability," |
Notes |
|
Envoyé |
Oui |
Condensat |
adversaries anyone attack browse can connection cybersecurity discovered enables entirely expands exploit have javascript local locally log4j log4shell machine means network new newly potentially private researchers servers surface trigger using vector version vulnerability vulnerable website websocket |
Tags |
Vulnerability
|
Stories |
|
Move |
|