DEV Community

Discussion on: Massive Log4j Java vulnerability: What it is & how to fix it?

Collapse
 
siy profile image
Sergiy Yevtushenko

The issue appears in two cases: when malicious input is part of format string (which is bad practice and usually avoided) and when format string explicitly refers a variable (contains pattern like ${object.property}) - frankly, I didn't even know that such syntax is supported. Finally, issue is not applicable to most recent versions of all supported JVM releases.

If to sum up: the hype is much louder than real issue is.