Apache Log4j2 Remote Code Injection
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.
How to fix it
Upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later).
What this check actually does
- Fingerprints the host — server, technologies, certificate and response headers.
- Runs the Apache Log4j2 Remote Code Injection detection against it.
- Runs a short pass for common misconfigurations, exposed files and TLS problems.
- Cross-references the detected versions against published CVEs.
Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.