All rules →
Rules / Java
SHIELD-JAVA-018

Log4Shell JNDI Lookup Injection

criticalJavaCWE-917CVSS 10

What it detects

A jndi lookup pattern in logged data can trigger remote code execution via Log4j.

How to fix

Upgrade Log4j and disable message lookups; never log unsanitized user input.

Scan your repo freeFull documentation
Back to all rules
SHIELD-JAVA-018: Log4Shell JNDI Lookup Injection — Zennoxa Shield