Background /What has happened?
A remote code execution vulnerability has been identified in Apache Log4j2 library, one of the most widely used Java-based logging utilities globally, via a .
Proof-of-concept code to exploit this vulnerability is .
Due to widespread use in popular frameworks a large number of third-party apps may also be vulnerable to exploits.
The ACSC is aware of scanning in attempts to locate vulnerable servers.
Mitigation / How do I stay secure?
Australian organisations who utilise Apache Log4j2 versions prior to 2.15.0 should review their patch level and update to the l.
Assistance / Where can I go for help?
/Public Release. View in full .