JNDI Code Injection due an outdated log4j component

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

JNDI Code Injection due an outdated log4j component

Post by Shane1145 »

It seems that the machine is affected by the latest CVE-2021-44228 which grants any authenticated user command execution. The vulnerability affects the remote asset forum.acronis.com and this issue allows to remote attackers to perfom Remote Code Execution via JNDI exfiltration.
Steps To Reproduce

https://hackerone.com/reports/1430622
Post Reply