Warning: Apache Log4j2 Java Deserialization Filter Bypass Could Enable Remote Code Execution, Mitigate Immediately!
ID: 8352fd98-ee17-5ef4-ae55-322a7ea3d043
STIX ID: report--8352fd98-ee17-5ef4-ae55-322a7ea3d043
A newly disclosed deserialization vulnerability in Apache Log4j2's FilteredObjectInputStream can allow remote code execution when an application accepts Java-serialized LogEvent objects that contain java.rmi.MarshalledObject; the nested deserialization bypasses Log4j's allowlist and can enable gadget-chain exploitation or DoS. The advisory stresses the exposure is narrower than Log4Shell (requiring serialized LogEvent receivers and specific classes), lists detection and mitigation steps (disable/remove serialized receivers, network restrictions, JVM/JEP-290 filters, reject MarshalledObject), and recommends monitoring for suspicious Java process activity while awaiting an official Log4j fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
