Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

使用CodeQL发现Log4j CVE-2021-44228 - 4xpl0r3r's blog #16

Open
4xpl0r3r opened this issue Feb 14, 2023 · 0 comments
Open

使用CodeQL发现Log4j CVE-2021-44228 - 4xpl0r3r's blog #16

4xpl0r3r opened this issue Feb 14, 2023 · 0 comments

Comments

@4xpl0r3r
Copy link
Owner

https://cn.4xpl0r3r.com/%E6%8A%80%E6%9C%AF%E5%BD%92%E7%BA%B3/%E4%BD%BF%E7%94%A8CodeQL%E5%8F%91%E7%8E%B0CVE-2021-44228/

虽然已经有了一个针对”Potential Log4J LDAP JNDI injection (CVE-2021-44228)”的实验性CWE-020 Query,但这次我想改写CWE-074,使其能够发现CVE-2021-44228

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant