Analyzing the Apache Log4j2 JNDI Injection Flaw and Obfuscation Methods

Apache Log4j2 remains one of the most prevalent logging libraries within the Java ecosystem. Versions up to 2.15.0-rc2 contain a critical Remote Code Execution weakness stemming from unsafe evaluation of user-supplied data embedded directly into log entries. The vulnerability exploits the framework's native support for Java Naming and Directory ...

Posted on Wed, 23 Sep 2026 16:17:21 +0000 by AtomicRax

Deep Dive into Apache Commons Collections Deserialization Chains: CC5 and CC7 Mechanics

Target Environment The demonstration relies on the following library versions and runtime configurations: Library: Apache Commons Collections 3.2.1 Runtime: OpenJDK 1.8 (Update 65) Both vulnerabilities involve modifications within the LazyMap.get() method. The following sections detail the execution flow and implementation for the CC5 and CC7 ...

Posted on Fri, 10 Jul 2026 17:12:22 +0000 by richei