2 thoughts on “Public Disclosure: Unpatched Log4j RCE Flaw in FilteredObjectInputStream, No CVE Assigned”

  1. Small correction: nobody from the Log4j project deleted the issue. The reporter did, along with their own GitHub account. For context, we received over 120 security reports in Q1 alone and they resulted in only 8 low-medium vulnerabilities (https://logging.apache.org/security.html). We don’t panic: we brew a good cup of coffee and deal with them. πŸ˜‰

Leave a Reply