Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Published 31 Aug 2026Updated 31 Aug 2026454 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Affected versions

Log4j2: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 51183AD Manager Plus 7122 - Remote Code Execution (RCE)Chan Nyein Wai2023-04-01VerifiedExploit-DB 50592Apache Log4j 2 - Remote Code Execution (RCE)kozmer2021-12-14VerifiedExploit-DB 50590Apache Log4j2 2.14.1 - Information Disclosureleonjza2021-12-14VerifiedPoC-in-GitHub · tangxiaofeng7/CVE-2021-44228-Apache-Log4j-RceApache Log4j 远程代码执行★ 89tangxiaofeng72021-12-09CandidatePoC-in-GitHub · Glease/HealerPatch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2★ 19Glease2021-12-09CandidatePoC-in-GitHub · jacobtread/L4J-Vuln-PatchThis tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch★ 5jacobtread2021-12-10CandidatePoC-in-GitHub · jas502n/Log4j2-CVE-2021-44228Remote Code Injection In Log4j★ 469jas502n2021-12-10CandidatePoC-in-GitHub · HyCraftHD/Log4J-RCE-Proof-Of-ConceptLog4j-RCE (CVE-2021-44228) Proof of Concept with additional information★ 182HyCraftHD2021-12-10CandidatePoC-in-GitHub · boundaryx/cloudrasp-log4j2一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.★ 126boundaryx2021-12-10CandidatePoC-in-GitHub · dbgee/CVE-2021-44228Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.★ 0dbgee2021-12-10CandidatePoC-in-GitHub · CreeperHost/Log4jPatcherA mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)★ 49CreeperHost2021-12-10CandidatePoC-in-GitHub · DragonSurvivalEU/RCECVE-2021-44228 fix★ 6DragonSurvivalEU2021-12-10CandidatePoC-in-GitHub · simonis/Log4jPatchDeploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process★ 108simonis2021-12-10CandidatePoC-in-GitHub · zlepper/CVE-2021-44228-Test-ServerA small server for verifing if a given java program is succeptibel to CVE-2021-44228★ 3zlepper2021-12-10CandidatePoC-in-GitHub · christophetd/log4shell-vulnerable-appSpring Boot web application vulnerable to Log4Shell (CVE-2021-44228).★ 1141christophetd2021-12-10CandidatePoC-in-GitHub · NorthwaveSecurity/log4jcheckA script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.★ 127NorthwaveSecurity2021-12-10CandidatePoC-in-GitHub · nkoneko/VictimAppVulnerable to CVE-2021-44228. trustURLCodebase is not required.★ 4nkoneko2021-12-10CandidatePoC-in-GitHub · lhotari/pulsar-docker-images-patch-CVE-2021-44228Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell★ 1lhotari2021-12-10CandidatePoC-in-GitHub · 1in9e/Apache-Log4j2-RCEApache Log4j2 RCE( CVE-2021-44228)验证环境★ 21in9e2021-12-10CandidatePoC-in-GitHub · KosmX/CVE-2021-44228-examplevulnerability POC★ 7KosmX2021-12-10CandidatePoC-in-GitHub · greymd/CVE-2021-44228Vulnerability CVE-2021-44228 checker★ 35greymd2021-12-10CandidatePoC-in-GitHub · mubix/CVE-2021-44228-Log4Shell-HashesHashes for vulnerable LOG4J versions★ 155mubix2021-12-10CandidatePoC-in-GitHub · OopsieWoopsie/mc-log4j-patcherCVE-2021-44228 server-side fix for minecraft servers.★ 7OopsieWoopsie2021-12-10CandidatePoC-in-GitHub · wheezysec/CVE-2021-44228-kusto★ 0wheezysec2021-12-10CandidatePoC-in-GitHub · izzyacademy/log4shell-mitigationMitigation for Log4Shell Security Vulnerability CVE-2021-44228★ 0izzyacademy2021-12-10CandidatePoC-in-GitHub · Kadantte/CVE-2021-44228-poclog4shell sample application (CVE-2021-44228)★ 0Kadantte2021-12-10CandidatePoC-in-GitHub · takito1812/log4j-detectSimple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading★ 195takito18122021-12-10CandidatePoC-in-GitHub · winnpixie/log4noshellA Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").★ 5winnpixie2021-12-10CandidatePoC-in-GitHub · Azeemering/CVE-2021-44228-DFIR-NotesCVE-2021-44228 DFIR Notes★ 7Azeemering2021-12-10CandidatePoC-in-GitHub · Puliczek/CVE-2021-44228-PoC-log4j-bypass-words🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks★ 948Puliczek2021-12-10CandidatePoC-in-GitHub · kozmer/log4j-shell-pocA Proof-Of-Concept for the CVE-2021-44228 vulnerability.★ 1848kozmer2021-12-10CandidatePoC-in-GitHub · alexandreroman/cve-2021-44228-workaround-buildpackBuildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)★ 3alexandreroman2021-12-10CandidatePoC-in-GitHub · Adikso/minecraft-log4j-honeypotMinecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam★ 106Adikso2021-12-10CandidatePoC-in-GitHub · racoon-rac/CVE-2021-44228★ 0racoon-rac2021-12-10CandidatePoC-in-GitHub · TheArqsz/CVE-2021-44228-PoC★ 0TheArqsz2021-12-10CandidatePoC-in-GitHub · 1lann/log4shelldetectRapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class paths inside files★ 451lann2021-12-11CandidatePoC-in-GitHub · binganao/Log4j2-RCELog4j2 CVE-2021-44228 复现和回显利用★ 2binganao2021-12-11CandidatePoC-in-GitHub · phoswald/sample-ldap-exploitA short demo of CVE-2021-44228★ 5phoswald2021-12-11CandidatePoC-in-GitHub · rakutentech/jndi-ldap-test-serverA minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.★ 11rakutentech2021-12-11CandidatePoC-in-GitHub · uint0/cve-2021-44228--spring-hibernateCVE-2021-44228 POC - Spring / Hibernate★ 1uint02021-12-11CandidatePoC-in-GitHub · saharNooby/log4j-vulnerability-patcher-agentFixes CVE-2021-44228 in log4j by patching JndiLookup class★ 3saharNooby2021-12-11CandidatePoC-in-GitHub · f0ng/log4j2burpscannerCVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks★ 842f0ng2021-12-11CandidatePoC-in-GitHub · M1ngGod/CVE-2021-44228-Log4j-lookup-Rce★ 4M1ngGod2021-12-11CandidatePoC-in-GitHub · byteboycn/CVE-2021-44228-Apache-Log4j-Rce★ 2byteboycn2021-12-11CandidatePoC-in-GitHub · lhotari/log4shell-mitigation-testerLog4Shell CVE-2021-44228 mitigation tester★ 16lhotari2021-12-11CandidatePoC-in-GitHub · toramanemre/log4j-rce-detect-waf-bypassA Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads★ 23toramanemre2021-12-11CandidatePoC-in-GitHub · logpresso/CVE-2021-44228-ScannerVulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228★ 860logpresso2021-12-11CandidatePoC-in-GitHub · vorburger/Log4j_CVE-2021-44228★ 3vorburger2021-12-11CandidatePoC-in-GitHub · gauthamg/log4j2021_vul_testTest the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228★ 0gauthamg2021-12-11CandidatePoC-in-GitHub · b-abderrahmane/CVE-2021-44228-playground★ 2b-abderrahmane2021-12-11CandidatePoC-in-GitHub · leetxyz/CVE-2021-44228-AdvisoriesList of company advisories log4j★ 0leetxyz2021-12-11CandidatePoC-in-GitHub · cado-security/log4shellContent to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228★ 1cado-security2021-12-11CandidatePoC-in-GitHub · WYSIIWYG/Log4J_0day_RCELog4j-RCE (CVE-2021-44228) Proof of Concept★ 0WYSIIWYG2021-12-11CandidatePoC-in-GitHub · mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraformA Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228★ 2mkhazamipour2021-12-11CandidatePoC-in-GitHub · Sh0ckFR/log4j-CVE-2021-44228-Public-IoCsPublic IoCs about log4j CVE-2021-44228★ 9Sh0ckFR2021-12-11CandidatePoC-in-GitHub · zzzz0317/log4j2-vulnerable-spring-appCVE-2021-44228★ 4zzzz03172021-12-11CandidatePoC-in-GitHub · datadavev/test-44228Simple demo of CVE-2021-44228★ 0datadavev2021-12-11CandidatePoC-in-GitHub · LemonCraftRu/JndiRemoverНебольшой мод направленный на устранение уязвимости CVE-2021-44228★ 0LemonCraftRu2021-12-11CandidatePoC-in-GitHub · zhangxvx/Log4j-Rec-CVE-2021-44228Apache Log4j CVE-2021-44228 漏洞复现★ 0zhangxvx2021-12-11CandidatePoC-in-GitHub · darkarnium/Log4j-CVE-DetectDetections for CVE-2021-44228 inside of nested binaries★ 35darkarnium2021-12-11CandidatePoC-in-GitHub · chilliwebs/CVE-2021-44228_Example★ 1chilliwebs2021-12-11CandidatePoC-in-GitHub · irgoncalves/f5-waf-enforce-sig-CVE-2021-44228This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device★ 6irgoncalves2021-12-11CandidatePoC-in-GitHub · jeffbryner/log4j-docker-vaccinedocker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228★ 2jeffbryner2021-12-11CandidatePoC-in-GitHub · mergebase/log4j-detectorA public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC★ 640mergebase2021-12-12CandidatePoC-in-GitHub · unlimitedsola/log4j2-rce-pocA bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).★ 3unlimitedsola2021-12-12CandidatePoC-in-GitHub · Jeromeyoung/log4j2burpscannerCVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名★ 32Jeromeyoung2021-12-12CandidatePoC-in-GitHub · corretto/hotpatch-for-apache-log4j2An agent to hotpatch the log4j RCE from CVE-2021-44228.★ 497corretto2021-12-12CandidatePoC-in-GitHub · alexandre-lavoie/python-log4rceAn All-In-One Pure Python PoC for CVE-2021-44228★ 178alexandre-lavoie2021-12-12CandidatePoC-in-GitHub · RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs★ 44RedDrip72021-12-12CandidatePoC-in-GitHub · mzlogin/CVE-2021-44228-DemoApache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP★ 2mzlogin2021-12-12CandidatePoC-in-GitHub · blake-fm/vcenter-log4jScript to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228★ 17blake-fm2021-12-12CandidatePoC-in-GitHub · uint0/cve-2021-44228-helpers★ 0uint02021-12-12CandidatePoC-in-GitHub · sud0x00/log4j-CVE-2021-44228CVE-2021-44228★ 5sud0x002021-12-12CandidatePoC-in-GitHub · DiCanio/CVE-2021-44228-docker-example★ 1DiCanio2021-12-12CandidatePoC-in-GitHub · mrlnstk/cve-2021-44228-minecraft-pocLog4J CVE-2021-44228 Minecraft PoC★ 5mrlnstk2021-12-12CandidatePoC-in-GitHub · RrUZi/Awesome-CVE-2021-44228An awesome curated list of repos for CVE-2021-44228. ``Apache Log4j 2``★ 1RrUZi2021-12-12CandidatePoC-in-GitHub · future-client/CVE-2021-44228Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)★ 66future-client2021-12-12CandidatePoC-in-GitHub · CodeShield-Security/Log4JShell-Bytecode-DetectorLocal Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)★ 49CodeShield-Security2021-12-12CandidatePoC-in-GitHub · Crane-Mocker/log4j-pocPoc of log4j2 (CVE-2021-44228)★ 0Crane-Mocker2021-12-12CandidatePoC-in-GitHub · dtact/divd-2021-00038--log4j-scannerScan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.★ 46dtact2021-12-12CandidatePoC-in-GitHub · kali-dass/CVE-2021-44228-log4ShellSample log4j shell exploit★ 1kali-dass2021-12-12CandidatePoC-in-GitHub · pravin-pp/log4j2-CVE-2021-44228★ 1pravin-pp2021-12-12CandidatePoC-in-GitHub · Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228★ 15Malwar3Ninja2021-12-12CandidatePoC-in-GitHub · urholaukkarinen/docker-log4shellDockerized Go app for testing the CVE-2021-44228 vulnerability★ 0urholaukkarinen2021-12-12CandidatePoC-in-GitHub · ssl/scan4log4jPython script that sends CVE-2021-44228 log4j payload requests to url list★ 6ssl2021-12-12CandidatePoC-in-GitHub · infiniroot/nginx-mitigate-log4shellMitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script★ 38infiniroot2021-12-12CandidatePoC-in-GitHub · lohanichaten/log4j-cve-2021-44228★ 0lohanichaten2021-12-12CandidatePoC-in-GitHub · authomize/log4j-log4shell-affectedLists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability★ 52authomize2021-12-12CandidatePoC-in-GitHub · guardicode/CVE-2021-44228_IoCsKnown IoCs for log4j framework vulnerability★ 0guardicode2021-12-12CandidatePoC-in-GitHub · fireflyingup/log4j-pocCVE-2021-44228 test demo★ 0fireflyingup2021-12-12CandidatePoC-in-GitHub · qingtengyun/cve-2021-44228-qingteng-patch★ 9qingtengyun2021-12-12CandidatePoC-in-GitHub · nccgroup/log4j-jndi-be-goneA Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.★ 72nccgroup2021-12-12CandidatePoC-in-GitHub · qingtengyun/cve-2021-44228-qingteng-online-patchHot-patch CVE-2021-44228 by exploiting the vulnerability itself.★ 25qingtengyun2021-12-12CandidatePoC-in-GitHub · tasooshi/horrors-log4shellA micro lab for CVE-2021-44228 (log4j)★ 2tasooshi2021-12-12CandidatePoC-in-GitHub · Hydragyrum/evil-rmi-serverAn evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228★ 12Hydragyrum2021-12-12CandidatePoC-in-GitHub · twseptian/spring-boot-log4j-cve-2021-44228-docker-labSpring Boot Log4j - CVE-2021-44228 Docker Lab★ 27twseptian2021-12-12CandidatePoC-in-GitHub · OlafHaalstra/log4jcheckCheck list of URLs against Log4j vulnerability CVE-2021-44228★ 5OlafHaalstra2021-12-12CandidatePoC-in-GitHub · Panyaprach/Prove-CVE-2021-44228★ 1Panyaprach2021-12-12CandidatePoC-in-GitHub · momos1337/Log4j-RCELog4j RCE - (CVE-2021-44228)★ 7momos13372021-12-12CandidatePoC-in-GitHub · cyberxml/log4j-pocA Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell★ 72cyberxml2021-12-12CandidatePoC-in-GitHub · corneacristian/Log4J-CVE-2021-44228-RCELog4J (CVE-2021-44228) Exploit with Remote Command Execution (RCE)★ 4corneacristian2021-12-12CandidatePoC-in-GitHub · Diverto/nse-log4shellNmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)★ 353Diverto2021-12-12CandidatePoC-in-GitHub · dotPY-hax/log4pypythonic pure python RCE exploit for CVE-2021-44228 log4shell★ 2dotPY-hax2021-12-12CandidatePoC-in-GitHub · sunnyvale-it/CVE-2021-44228-PoCCVE-2021-44228 (Log4Shell) Proof of Concept★ 8sunnyvale-it2021-12-12CandidatePoC-in-GitHub · maxant/log4j2-CVE-2021-44228★ 0maxant2021-12-13CandidatePoC-in-GitHub · atnetws/fail2ban-log4jfail2ban filter that catches attacks againts log4j CVE-2021-44228★ 8atnetws2021-12-13CandidatePoC-in-GitHub · kimobu/cve-2021-44228Some files for red team/blue team investigations into CVE-2021-44228★ 1kimobu2021-12-13CandidatePoC-in-GitHub · ph0lk3r/anti-jndiFun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.★ 2ph0lk3r2021-12-13CandidatePoC-in-GitHub · bigsizeme/Log4j-checklog4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload★ 71bigsizeme2021-12-13CandidatePoC-in-GitHub · pedrohavay/exploit-CVE-2021-44228This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).★ 20pedrohavay2021-12-13CandidatePoC-in-GitHub · fireeye/CVE-2021-44228OpenIOC rules to facilitate hunting for indicators of compromise★ 37fireeye2021-12-13CandidatePoC-in-GitHub · fullhunt/log4j-scanA fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228★ 3422fullhunt2021-12-13CandidatePoC-in-GitHub · rubo77/log4j_checker_betaa fast check, if your server could be vulnerable to CVE-2021-44228★ 247rubo772021-12-13CandidatePoC-in-GitHub · thecyberneh/Log4j-RCE-ExploiterScanner for Log4j RCE CVE-2021-44228★ 11thecyberneh2021-12-13CandidatePoC-in-GitHub · halibobor/log4j2CVE-2021-44228★ 1halibobor2021-12-13CandidatePoC-in-GitHub · sourcegraph/log4j-cve-code-search-resourcesUsing code search to help fix/mitigate log4j CVE-2021-44228★ 1sourcegraph2021-12-13CandidatePoC-in-GitHub · thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832Log4J CVE-2021-44228 : Mitigation Cheat Sheet★ 2thedevappsecguy2021-12-13CandidatePoC-in-GitHub · helsecert/CVE-2021-44228★ 1helsecert2021-12-13CandidatePoC-in-GitHub · markuman/aws-log4j-mitigationsCVE-2021-44228 log4j mitigation using aws wafv2 with ansible★ 0markuman2021-12-13CandidatePoC-in-GitHub · tuyenee/Log4shellA lab for playing around with the Log4J CVE-2021-44228★ 0tuyenee2021-12-13CandidatePoC-in-GitHub · JiuBanSec/Log4j-CVE-2021-44228Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)★ 1JiuBanSec2021-12-13CandidatePoC-in-GitHub · ycdxsb/Log4Shell-CVE-2021-44228-ENVLog4Shell Docker Env★ 4ycdxsb2021-12-13CandidatePoC-in-GitHub · avwolferen/Sitecore.Solr-log4j-mitigationThis repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228★ 2avwolferen2021-12-13CandidatePoC-in-GitHub · george-petrakis/log4j-scanner-CVE-2021-44228Simple tool for scanning entire directories for attempts of CVE-2021-44228★ 2george-petrakis2021-12-13CandidatePoC-in-GitHub · Camphul/log4shell-spring-framework-researchResearch into the implications of CVE-2021-44228 in Spring based applications.★ 0Camphul2021-12-13CandidatePoC-in-GitHub · lov3r/cve-2021-44228-log4j-exploitsCVE-2021-4428 复现★ 0lov3r2021-12-13CandidatePoC-in-GitHub · sinakeshmiri/log4jScansimple python scanner to check if your network is vulnerable to CVE-2021-44228★ 4sinakeshmiri2021-12-13CandidatePoC-in-GitHub · 0xDexter0us/Log4J-ScannerBurp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.★ 1010xDexter0us2021-12-13CandidatePoC-in-GitHub · LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228★ 0LutziGoz2021-12-13CandidatePoC-in-GitHub · 0xsyr0/Log4ShellThis repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.★ 60xsyr02021-12-13CandidatePoC-in-GitHub · 1hakusai1/log4j-rce-CVE-2021-44228log4j2 CVE-2021-44228 POC★ 01hakusai12021-12-13CandidatePoC-in-GitHub · jeffli1024/log4j-rce-testCVE-2021-44228 - Apache log4j RCE quick test★ 2jeffli10242021-12-13CandidatePoC-in-GitHub · zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service★ 13zsolt-halo2021-12-13CandidatePoC-in-GitHub · manuel-alvarez-alvarez/log4j-cve-2021-44228Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...★ 5manuel-alvarez-alvarez2021-12-13CandidatePoC-in-GitHub · VNYui/CVE-2021-44228Mass recognition tool for CVE-2021-44228★ 0VNYui2021-12-13CandidatePoC-in-GitHub · justakazh/Log4j-CVE-2021-44228Mass Check Vulnerable Log4j CVE-2021-44228★ 6justakazh2021-12-13CandidatePoC-in-GitHub · irgoncalves/f5-waf-quick-patch-cve-2021-44228This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode★ 3irgoncalves2021-12-13CandidatePoC-in-GitHub · madCdan/JndiLookupSome tools to help mitigating Apache Log4j 2 CVE-2021-44228★ 3madCdan2021-12-13CandidatePoC-in-GitHub · Koupah/MC-Log4j-PatcherA singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).★ 4Koupah2021-12-13CandidatePoC-in-GitHub · AlexandreHeroux/Fix-CVE-2021-44228Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/★ 6AlexandreHeroux2021-12-13CandidatePoC-in-GitHub · kossatzd/log4j-CVE-2021-44228-testdemo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability★ 0kossatzd2021-12-13CandidatePoC-in-GitHub · tobiasoed/log4j-CVE-2021-44228★ 0tobiasoed2021-12-13CandidatePoC-in-GitHub · hackinghippo/log4shell_ioc_ipslog4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)★ 37hackinghippo2021-12-13CandidatePoC-in-GitHub · p3dr16k/log4j-1.2.15-modlog4j version 1 with a patch for CVE-2021-44228 vulnerability★ 1p3dr16k2021-12-13CandidatePoC-in-GitHub · claranet/ansible-role-log4shellFind Log4Shell CVE-2021-44228 on your system★ 11claranet2021-12-13CandidatePoC-in-GitHub · taurusxin/CVE-2021-44228★ 2taurusxin2021-12-13CandidatePoC-in-GitHub · corelight/cve-2021-44228Log4j Exploit Detection Logic for Zeek★ 19corelight2021-12-13CandidatePoC-in-GitHub · rodfer0x80/log4j2-prosecutorCVE-2021-44228★ 0rodfer0x802021-12-13CandidatePoC-in-GitHub · yanghaoi/CVE-2021-44228_Log4ShellLog4Shell A test for CVE-2021-44228★ 0yanghaoi2021-12-13CandidatePoC-in-GitHub · lfama/log4j_checkerPython3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.★ 8lfama2021-12-13CandidatePoC-in-GitHub · threatmonit/Log4j-IOCsPublic IOCs about log4j CVE-2021-44228★ 3threatmonit2021-12-13CandidatePoC-in-GitHub · ben-smash/l4j-infoCompiling links of value i find regarding CVE-2021-44228★ 0ben-smash2021-12-13CandidatePoC-in-GitHub · strawhatasif/log4j-testDemonstration of CVE-2021-44228 with a possible strategic fix.★ 0strawhatasif2021-12-13CandidatePoC-in-GitHub · giterlizzi/nmap-log4shellNmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)★ 79giterlizzi2021-12-13CandidatePoC-in-GitHub · tica506/Siem-queries-for-CVE-2021-44228★ 0tica5062021-12-13CandidatePoC-in-GitHub · chilit-nl/log4shell-exampleThe goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.★ 0chilit-nl2021-12-13CandidatePoC-in-GitHub · Occamsec/log4j-checkerBash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.★ 4Occamsec2021-12-13CandidatePoC-in-GitHub · snatalius/log4j2-CVE-2021-44228-poc-localJust a personal proof of concept of CVE-2021-44228 on log4j2★ 0snatalius2021-12-13CandidatePoC-in-GitHub · Contrast-Security-OSS/CVE-2021-44228Professional Service scripts to aid in the identification of affected Java applications in TeamServer★ 0Contrast-Security-OSS2021-12-13CandidatePoC-in-GitHub · back2root/log4shell-rexPCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs★ 291back2root2021-12-13CandidatePoC-in-GitHub · alexbakker/log4shell-toolsTool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046★ 86alexbakker2021-12-13CandidatePoC-in-GitHub · perryflynn/find-log4jFind log4j for CVE-2021-44228 on some places * Log4Shell★ 2perryflynn2021-12-13CandidatePoC-in-GitHub · alpacamybags118/log4j-cve-2021-44228-sampleSample docker-compose setup to show how this exploit works★ 2alpacamybags1182021-12-14CandidatePoC-in-GitHub · sandarenu/log4j2-issue-checkDemo project to evaluate Log4j2 Vulnerability | CVE-2021-44228★ 0sandarenu2021-12-14CandidatePoC-in-GitHub · roticagas/CVE-2021-44228-Demo★ 0roticagas2021-12-14CandidatePoC-in-GitHub · Woahd/log4j-urlscannerSimple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading★ 1Woahd2021-12-14CandidatePoC-in-GitHub · faisalfs10x/Log4j2-CVE-2021-44228-revshellLog4j2 CVE-2021-44228 revshell, ofc it suck!!★ 18faisalfs10x2021-12-14CandidatePoC-in-GitHub · gcmurphy/chk_log4jSome siimple checks to see if JAR file is vulnerable to CVE-2021-44228★ 1gcmurphy2021-12-14CandidatePoC-in-GitHub · 0xInfection/LogMePwnA fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.★ 3950xInfection2021-12-14CandidatePoC-in-GitHub · toramanemre/apache-solr-log4j-CVE-2021-44228A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228★ 4toramanemre2021-12-14CandidatePoC-in-GitHub · codiobert/log4j-scannerCheck CVE-2021-44228 vulnerability★ 3codiobert2021-12-14CandidatePoC-in-GitHub · cbuschka/log4j2-rce-recapLittle recap of the log4j2 remote code execution (CVE-2021-44228)★ 0cbuschka2021-12-14CandidatePoC-in-GitHub · andrii-kovalenko-celonis/log4j-vulnerability-demoEndpoint to test CVE-2021-44228 – Log4j 2★ 0andrii-kovalenko-celonis2021-12-14CandidatePoC-in-GitHub · dark-ninja10/Log4j-CVE-2021-44228On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string. Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it "Log4Shell" for short.★ 0dark-ninja102021-12-14CandidatePoC-in-GitHub · fox-it/log4j-finderFind vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)★ 439fox-it2021-12-14CandidatePoC-in-GitHub · 34zY/JNDI-Exploit-1.2-log4shellDetails : CVE-2021-44228★ 034zY2021-12-14CandidatePoC-in-GitHub · didoatanasov/cve-2021-44228★ 0didoatanasov2021-12-14CandidatePoC-in-GitHub · ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228CVE-2021-44228★ 0ShaneKingBlog2021-12-14CandidatePoC-in-GitHub · wortell/log4jRepo containing all info, scripts, etc. related to CVE-2021-44228★ 10wortell2021-12-14CandidatePoC-in-GitHub · municipalparkingservices/CVE-2021-44228-Scanner★ 0municipalparkingservices2021-12-14CandidatePoC-in-GitHub · BinaryDefense/log4j-honeypot-flaskInternal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228★ 149BinaryDefense2021-12-14CandidatePoC-in-GitHub · MalwareTech/Log4jToolsTools for investigating Log4j CVE-2021-44228★ 94MalwareTech2021-12-14CandidatePoC-in-GitHub · mufeedvh/log4jailA firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.★ 21mufeedvh2021-12-14CandidatePoC-in-GitHub · guerzon/log4shellpocSimple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)★ 1guerzon2021-12-14CandidatePoC-in-GitHub · ab0x90/CVE-2021-44228_PoC★ 16ab0x902021-12-14CandidatePoC-in-GitHub · stripe/log4j-remediation-toolsTools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)★ 40stripe2021-12-14CandidatePoC-in-GitHub · xsultan/log4jshieldLog4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher★ 13xsultan2021-12-14CandidatePoC-in-GitHub · HynekPetrak/log4shell-finderFastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.★ 39HynekPetrak2021-12-14CandidatePoC-in-GitHub · 0xThiebaut/CVE-2021-44228CVE-2021-44228 Response Scripts★ 00xThiebaut2021-12-14CandidatePoC-in-GitHub · CERTCC/CVE-2021-44228_scannerScanners for Jar files that may be vulnerable to CVE-2021-44228★ 350CERTCC2021-12-14CandidatePoC-in-GitHub · CrackerCat/CVE-2021-44228-Log4j-Payloads★ 3CrackerCat2021-12-15CandidatePoC-in-GitHub · dbzoo/log4j_scannerFast filesystem scanner for CVE-2021-44228★ 4dbzoo2021-12-15CandidatePoC-in-GitHub · jeremyrsellars/CVE-2021-44228_scannerAims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.★ 0jeremyrsellars2021-12-15CandidatePoC-in-GitHub · VinniMarcon/Log4j-UpdaterLog4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228★ 2VinniMarcon2021-12-15CandidatePoC-in-GitHub · bhprin/log4j-vulThis project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228★ 0bhprin2021-12-15CandidatePoC-in-GitHub · rgl/log4j-log4shell-playgroundA playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations★ 1rgl2021-12-15CandidatePoC-in-GitHub · anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228A one-stop repo/ information hub for all log4j vulnerability-related information.★ 2anuvindhs2021-12-15CandidatePoC-in-GitHub · KeysAU/Get-log4j-Windows.ps1Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228★ 7KeysAU2021-12-15CandidatePoC-in-GitHub · kubearmor/log4j-CVE-2021-44228Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228★ 9kubearmor2021-12-15CandidatePoC-in-GitHub · redhuntlabs/Log4JHuntAn automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.★ 47redhuntlabs2021-12-15CandidatePoC-in-GitHub · mss/log4shell-hotfix-side-effectTest case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions★ 3mss2021-12-15CandidatePoC-in-GitHub · MeterianHQ/log4j-vuln-coverage-checkA simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)★ 0MeterianHQ2021-12-15CandidatePoC-in-GitHub · mitiga/log4shell-cloud-scannerwe are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in their AWS account. The script enables security teams to identify external-facing AWS assets by running the exploit on them, and thus be able to map them and quickly patch them★ 14mitiga2021-12-15CandidatePoC-in-GitHub · isuruwa/Log4jA scanner and a proof of sample exploit for log4j RCE CVE-2021-44228★ 6isuruwa2021-12-15CandidatePoC-in-GitHub · honeynet/log4shell-dataData we are receiving from our honeypots about CVE-2021-44228★ 0honeynet2021-12-15CandidatePoC-in-GitHub · inettgmbh/checkmk-log4j-scannerScans for Log4j versions effected by CVE-2021-44228★ 4inettgmbh2021-12-15CandidatePoC-in-GitHub · b1tm0n3r/CVE-2021-44228CVE-2021-44228 demo webapp★ 0b1tm0n3r2021-12-15CandidatePoC-in-GitHub · VerveIndustrialProtection/CVE-2021-44228-Log4j★ 1VerveIndustrialProtection2021-12-15CandidatePoC-in-GitHub · alenazi90/log4jAn automated header extensive scanner for detecting log4j RCE CVE-2021-44228★ 2alenazi902021-12-15CandidatePoC-in-GitHub · pmontesd/log4j-cve-2021-44228Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell★ 3pmontesd2021-12-15CandidatePoC-in-GitHub · LiveOverflow/log4shellSmall example repo for looking into log4j CVE-2021-44228★ 72LiveOverflow2021-12-15CandidatePoC-in-GitHub · aws-samples/kubernetes-log4j-cve-2021-44228-node-agent★ 2aws-samples2021-12-15CandidatePoC-in-GitHub · michaelsanford/Log4Shell-HoneypotDockerized honeypot for CVE-2021-44228.★ 4michaelsanford2021-12-15CandidatePoC-in-GitHub · thomaspatzke/Log4PotA honeypot for the Log4Shell vulnerability (CVE-2021-44228).★ 94thomaspatzke2021-12-15CandidatePoC-in-GitHub · ubitech/cve-2021-44228-rce-pocA Remote Code Execution PoC for Log4Shell (CVE-2021-44228)★ 3ubitech2021-12-15CandidatePoC-in-GitHub · rv4l3r3/log4v-vuln-checkThis script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).★ 0rv4l3r32021-12-16CandidatePoC-in-GitHub · dpomnean/log4j_scanner_wrapperlog4j vulnerability wrapper scanner for CVE-2021-44228★ 1dpomnean2021-12-16CandidatePoC-in-GitHub · roxas-tan/CVE-2021-44228This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce★ 10roxas-tan2021-12-16CandidatePoC-in-GitHub · shamo0/CVE-2021-44228log4shell (CVE-2021-44228) scanning tool★ 4shamo02021-12-16CandidatePoC-in-GitHub · snow0715/log4j-Scan-BurpsuiteLog4j漏洞(CVE-2021-44228)的Burpsuite检测插件★ 13snow07152021-12-16CandidatePoC-in-GitHub · Joefreedy/Log4j-Windows-ScannerCVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.★ 3Joefreedy2021-12-16CandidatePoC-in-GitHub · Nanitor/log4fixDetect and fix log4j log4shell vulnerability (CVE-2021-44228)★ 12Nanitor2021-12-16CandidatePoC-in-GitHub · korteke/log4shell-demoSimple webapp that is vulnerable to Log4Shell (CVE-2021-44228)★ 2korteke2021-12-16CandidatePoC-in-GitHub · recanavar/vuln_spring_log4j2Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228★ 0recanavar2021-12-16CandidatePoC-in-GitHub · DXC-StrikeForce/Burp-Log4j-HammerTimeBurp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046★ 8DXC-StrikeForce2021-12-16CandidatePoC-in-GitHub · andalik/log4j-filescanScanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de arquivos JAR (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 e CVE-2021-44832)★ 1andalik2021-12-16CandidatePoC-in-GitHub · lonecloud/CVE-2021-44228-Apache-Log4jCVE-2021-44228-Apache-Log4j★ 0lonecloud2021-12-16CandidatePoC-in-GitHub · gyaansastra/CVE-2021-44228Log4Shell CVE-2021-44228 Vulnerability Scanner and POC★ 1gyaansastra2021-12-16CandidatePoC-in-GitHub · axisops/CVE-2021-44228log4j mitigation work★ 0axisops2021-12-16CandidatePoC-in-GitHub · kal1gh0st/MyLog4ShellSimple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading★ 1kal1gh0st2021-12-16CandidatePoC-in-GitHub · hozyx/log4shellApplications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the presence of JndiLookup.class.★ 0hozyx2021-12-16CandidatePoC-in-GitHub · andypitcher/Log4J_checkerLog4J checker for Apache CVE-2021-44228★ 0andypitcher2021-12-16CandidatePoC-in-GitHub · Vulnmachines/log4j-cve-2021-44228★ 0Vulnmachines2021-12-16CandidatePoC-in-GitHub · kannthu/CVE-2021-44228-Apache-Log4j-Rce★ 0kannthu2021-12-16CandidatePoC-in-GitHub · Kr0ff/CVE-2021-44228Log4Shell Proof of Concept (CVE-2021-44228)★ 4Kr0ff2021-12-16CandidatePoC-in-GitHub · suuhm/log4shell4shellLog4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell★ 5suuhm2021-12-16CandidatePoC-in-GitHub · wajda/log4shell-test-exploitTest exploit of CVE-2021-44228★ 0wajda2021-12-17CandidatePoC-in-GitHub · obscuritylabs/log4shell-poc-labA lab demonstration of the log4shell vulnerability: CVE-2021-44228★ 9obscuritylabs2021-12-17CandidatePoC-in-GitHub · Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228Script - Workaround instructions to address CVE-2021-44228 in vCenter Server★ 2Fazmin2021-12-17CandidatePoC-in-GitHub · Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCEPoC RCE Log4j CVE-2021-4428 para pruebas★ 0Grupo-Kapa-72021-12-17CandidatePoC-in-GitHub · sysadmin0815/Fix-Log4j-PowershellScriptLog4Shell mitigation (CVE-2021-44228) - search and remove JNDI class from *log4j*.jar files on the system with Powershell (Windows)★ 0sysadmin08152021-12-17CandidatePoC-in-GitHub · RenYuH/log4j-lookups-vulnerabilityLog4j2 Vulnerability (CVE-2021-44228)★ 0RenYuH2021-12-17CandidatePoC-in-GitHub · scheibling/py-log4shellscannerScanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)★ 0scheibling2021-12-17CandidatePoC-in-GitHub · zaneef/CVE-2021-44228Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione★ 0zaneef2021-12-17CandidatePoC-in-GitHub · metodidavidovic/log4j-quick-scanScan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.★ 0metodidavidovic2021-12-17CandidatePoC-in-GitHub · WatchGuard-Threat-Lab/log4shell-iocsA collection of IOCs for CVE-2021-44228 also known as Log4Shell★ 0WatchGuard-Threat-Lab2021-12-17CandidatePoC-in-GitHub · Aschen/log4j-patchedProvide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself★ 1Aschen2021-12-17CandidatePoC-in-GitHub · nikolas-charalambidis/cve-2021-44228A simple simulation of the infamous CVE-2021-44228 issue.★ 0nikolas-charalambidis2021-12-17CandidatePoC-in-GitHub · m0rath/detect-log4j-exploitableCVE-2021-44228★ 0m0rath2021-12-17CandidatePoC-in-GitHub · nu11secur1ty/CVE-2021-44228-VULN-APP★ 1nu11secur1ty2021-12-17CandidatePoC-in-GitHub · ankur-katiyar/log4j-dockerDocker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)★ 5ankur-katiyar2021-12-17CandidatePoC-in-GitHub · immunityinc/Log4j-JNDIServerThis project will help to test the Log4j CVE-2021-44228 vulnerability.★ 9immunityinc2021-12-17CandidatePoC-in-GitHub · DANSI/PowerShell-Log4J-Scannercan find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046★ 0DANSI2021-12-18CandidatePoC-in-GitHub · suniastar/scan-log4shellA scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it★ 0suniastar2021-12-18CandidatePoC-in-GitHub · shivakumarjayaraman/log4jvulnerability-CVE-2021-44228An attempt to understand the log4j vulnerability by looking through the code★ 0shivakumarjayaraman2021-12-18CandidatePoC-in-GitHub · j3kz/CVE-2021-44228-PoCSelf-contained lab environment that runs the exploit safely, all from docker compose★ 0j3kz2021-12-18CandidatePoC-in-GitHub · Apipia/log4j-pcap-activityA fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)★ 1Apipia2021-12-18CandidatePoC-in-GitHub · axelcurmi/log4shell-docker-labLog4Shell (CVE-2021-44228) docker lab★ 0axelcurmi2021-12-18CandidatePoC-in-GitHub · otaviokr/log4j-2021-vulnerability-studyThis is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it works!★ 0otaviokr2021-12-18CandidatePoC-in-GitHub · kkyehit/log4j_CVE-2021-44228★ 0kkyehit2021-12-19CandidatePoC-in-GitHub · trickyearlobe/inspec-log4jAn Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046★ 1trickyearlobe2021-12-19CandidatePoC-in-GitHub · TheInterception/Log4J-Simulation-ToolVulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104★ 4TheInterception2021-12-19CandidatePoC-in-GitHub · KeysAU/Get-log4j-Windows-localIdentifying all log4j components across on local windows servers. CVE-2021-44228★ 5KeysAU2021-12-19CandidatePoC-in-GitHub · mschmnet/Log4Shell-demoDemo to show how Log4Shell / CVE-2021-44228 vulnerability works★ 7mschmnet2021-12-19CandidatePoC-in-GitHub · Rk-000/Log4j_scan_AdvanceA fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228★ 1Rk-0002021-12-19CandidatePoC-in-GitHub · puzzlepeaches/Log4jCenterExploiting CVE-2021-44228 in vCenter for remote code execution and more.★ 103puzzlepeaches2021-12-19CandidatePoC-in-GitHub · Labout/log4shell-rmi-pocA Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI★ 8Labout2021-12-19CandidatePoC-in-GitHub · TotallyNotAHaxxer/f-for-javaa project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD★ 0TotallyNotAHaxxer2021-12-20CandidatePoC-in-GitHub · spasam/log4j2-exploitlog4j2 Log4Shell CVE-2021-44228 proof of concept★ 2spasam2021-12-20CandidatePoC-in-GitHub · bumheehan/cve-2021-44228-log4j-test★ 0bumheehan2021-12-20CandidatePoC-in-GitHub · Y0-kan/Log4jShell-Scanlog4j2 RCE漏洞(CVE-2021-44228)内网扫描器,可用于在不出网的条件下进行漏洞扫描,帮助企业内部快速发现Log4jShell漏洞。★ 38Y0-kan2021-12-20CandidatePoC-in-GitHub · julian911015/Log4j-Scanner-ExploitScript en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.★ 2julian9110152021-12-20CandidatePoC-in-GitHub · intel-xeon/CVE-2021-44228---detection-with-PowerShell★ 0intel-xeon2021-12-20CandidatePoC-in-GitHub · chandru-gunasekaran/log4j-fix-CVE-2021-44228Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228★ 2chandru-gunasekaran2021-12-20CandidatePoC-in-GitHub · snapattack/damn-vulnerable-log4j-appVulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack★ 5snapattack2021-12-20CandidatePoC-in-GitHub · r00thunter/Log4Shell-ScannerPython script to detect Log4Shell Vulnerability CVE-2021-44228★ 0r00thunter2021-12-21CandidatePoC-in-GitHub · mn-io/log4j-spring-vuln-pocPOC for CVE-2021-44228 within Springboot★ 1mn-io2021-12-21CandidatePoC-in-GitHub · rejupillai/log4j2-hack-springbootLog4j2 CVE-2021-44228 hack demo for a springboot app★ 0rejupillai2021-12-21CandidatePoC-in-GitHub · lucab85/log4j-cve-2021-44228Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)★ 57lucab852021-12-21CandidatePoC-in-GitHub · BabooPan/Log4Shell-CVE-2021-44228-DemoLog4Shell Demo with AWS★ 2BabooPan2021-12-22CandidatePoC-in-GitHub · ossie-git/log4shell_sentinelA Smart Log4Shell/Log4j/CVE-2021-44228 Scanner★ 14ossie-git2021-12-22CandidatePoC-in-GitHub · r00thunter/Log4ShellGeneric Scanner for Apache log4j RCE CVE-2021-44228★ 7r00thunter2021-12-22CandidatePoC-in-GitHub · ssl-user-en/Log4j-Scanner-ExploitScript en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.★ 0ssl-user-en2021-12-22CandidatePoC-in-GitHub · BJLIYANLIANG/log4j-scannerLog4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS★ 0BJLIYANLIANG2021-12-22CandidatePoC-in-GitHub · badb33f/Apache-Log4j-POCProof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228★ 3badb33f2021-12-22CandidatePoC-in-GitHub · TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploitopen detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability★ 7TaroballzChen2021-12-23CandidatePoC-in-GitHub · lucab85/ansible-role-log4shellAnsible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).★ 4lucab852021-12-23CandidatePoC-in-GitHub · grimch/log4j-CVE-2021-44228-workaroundgeneral purpose workaround for the log4j CVE-2021-44228 vulnerability★ 0grimch2021-12-24CandidatePoC-in-GitHub · cybersecurityworks553/log4j-shell-cswA Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.★ 8cybersecurityworks5532021-12-24CandidatePoC-in-GitHub · Toolsec/log4j-scanCVE-2021-44228 检查工具★ 0Toolsec2021-12-24CandidatePoC-in-GitHub · puzzlepeaches/Log4jUnifiExploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.★ 169puzzlepeaches2021-12-24CandidatePoC-in-GitHub · many-fac3d-g0d/apache-tomcat-log4jLog4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat★ 5many-fac3d-g0d2021-12-24CandidatePoC-in-GitHub · marcourbano/CVE-2021-44228PoC for CVE-2021-44228.★ 7marcourbano2021-12-24CandidatePoC-in-GitHub · bsigouin/log4shell-vulnerable-appSpring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.★ 0bsigouin2021-12-24CandidatePoC-in-GitHub · ToxicEnvelope/XSYS-Log4J2Shell-Exthis repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research★ 0ToxicEnvelope2021-12-25CandidatePoC-in-GitHub · felipe8398/ModSec-log4j2Regra ModSec para proteção log4j2 - CVE-2021-44228★ 0felipe83982021-12-27CandidatePoC-in-GitHub · c3-h2/Log4j_Attacker_IPListCVE-2021-44228★ 0c3-h22021-12-27CandidatePoC-in-GitHub · mazhar-hassan/log4j-vulnerabilityLog4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j★ 0mazhar-hassan2021-12-27CandidatePoC-in-GitHub · s-retlaw/l4s_pocLog4Shell (Cve-2021-44228) Proof Of Concept★ 0s-retlaw2021-12-27CandidatePoC-in-GitHub · Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main★ 0Ravid-CheckMarx2021-12-27CandidatePoC-in-GitHub · yesspider-hacker/log4j-payload-generatorlog4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228★ 4yesspider-hacker2021-12-27CandidatePoC-in-GitHub · LinkMJB/log4shell_scannerQuick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability★ 0LinkMJB2021-12-27CandidatePoC-in-GitHub · NS-Sp4ce/Vm4JA tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager★ 209NS-Sp4ce2021-12-28CandidatePoC-in-GitHub · PoneyClairDeLune/LogJackFixA spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.★ 0PoneyClairDeLune2021-12-28CandidatePoC-in-GitHub · MarceloLeite2604/log4j-vulnerabilityPresents how to exploit CVE-2021-44228 vulnerability.★ 1MarceloLeite26042021-12-30CandidatePoC-in-GitHub · romanutti/log4shell-vulnerable-appThis repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.★ 0romanutti2021-12-31CandidatePoC-in-GitHub · marklindsey11/-CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVE-2021-44228-https-nvd.Log4j Vulnerability Scanner★ 0marklindsey112022-01-01CandidatePoC-in-GitHub · Timborin0/log4j-dork-scannerA script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks★ 0Timborin02022-01-01CandidatePoC-in-GitHub · marklindsey11/gh-repo-clone-marklindsey11--CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVLog4j-Scanner★ 0marklindsey112022-01-01CandidatePoC-in-GitHub · mklinkj/log4j2-testLog4j2 LDAP 취약점 테스트 (CVE-2021-44228)★ 0mklinkj2022-01-03CandidatePoC-in-GitHub · 4jfinder/4jfinder.github.ioSearchable page for CISA Log4j (CVE-2021-44228) Affected Vendor & Software List★ 64jfinder2022-01-04CandidatePoC-in-GitHub · alexpena5635/CVE-2021-44228_scanner-main-Modified-★ 0alexpena56352022-01-05CandidatePoC-in-GitHub · kanitan/log4j2-web-vulnerableA vulnerable web app for log4j2 RCE(CVE-2021-44228) exploit test.★ 0kanitan2022-01-05CandidatePoC-in-GitHub · mr-r3b00t/CVE-2021-44228Backdoor detection for VMware view★ 13mr-r3b00t2022-01-05CandidatePoC-in-GitHub · ChandanShastri/Log4j_Vulnerability_DemoA simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )★ 3ChandanShastri2022-01-05CandidatePoC-in-GitHub · puzzlepeaches/Log4jHorizonExploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.★ 120puzzlepeaches2022-01-05CandidatePoC-in-GitHub · Vulnmachines/log4jshell_CVE-2021-44228Log4jshell - CVE-2021-44228★ 2Vulnmachines2022-01-07CandidatePoC-in-GitHub · mr-vill4in/log4j-fuzzerCVE-2021-44228★ 3mr-vill4in2022-01-08CandidatePoC-in-GitHub · nix-xin/vuln4japiA vulnerable Java based REST API for demonstrating CVE-2021-44228 (log4shell).★ 1nix-xin2022-01-08CandidatePoC-in-GitHub · maximofernandezriera/CVE-2021-44228This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce★ 5maximofernandezriera2022-01-09CandidatePoC-in-GitHub · mebibite/log4jhoundCreated after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.★ 0mebibite2022-01-09CandidatePoC-in-GitHub · 3pplus/loguccinoScan and patch tool for CVE-2021-44228 and related log4j concerns.★ 03pplus2022-01-10CandidatePoC-in-GitHub · jxerome/log4shellDémo du fonctionnement de log4shell (CVE-2021-44228)★ 0jxerome2022-01-12CandidatePoC-in-GitHub · solitarysp/Log4j-CVE-2021-44228★ 0solitarysp2022-01-13CandidatePoC-in-GitHub · atlassion/log4j-exploit-builderScript to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell★ 0atlassion2022-01-13CandidatePoC-in-GitHub · atlassion/RS4LOGJ-CVE-2021-44228Fix: CVE-2021-44228 4LOGJ★ 0atlassion2022-01-13CandidatePoC-in-GitHub · sdogancesur/log4j_github_repositoryThis work includes testing and improvement tools for CVE-2021-44228(log4j).★ 1sdogancesur2022-01-13CandidatePoC-in-GitHub · jrocia/Search-log4Jvuln-AppScanSTDThis Pwsh script run AppScan Standard scans against a list of web sites (URLs.txt) checking for Log4J (CVE-2021-44228) vulnerability★ 0jrocia2022-01-14CandidatePoC-in-GitHub · aajuvonen/log4stdinA Java application intentionally vulnerable to CVE-2021-44228★ 0aajuvonen2022-01-16CandidatePoC-in-GitHub · arnaudluti/PS-CVE-2021-44228Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.★ 0arnaudluti2022-01-17CandidatePoC-in-GitHub · ColdFusionX/CVE-2021-44228-Log4Shell-POCPOC for Infamous Log4j CVE-2021-44228★ 2ColdFusionX2022-01-18CandidatePoC-in-GitHub · robrankin/cve-2021-44228-waf-testsTesting WAF protection against CVE-2021-44228 Log4Shell★ 0robrankin2022-01-20CandidatePoC-in-GitHub · 0xalwayslucky/log4j-polkit-pocvulnerable setup to display an attack chain of log4j CVE-2021-44228 with privilege escalation to root using the polkit exploit CVE-2021-4034★ 10xalwayslucky2022-01-27CandidatePoC-in-GitHub · y-security/yLog4jPortSwigger Burp Plugin for the Log4j (CVE-2021-44228)★ 2y-security2022-01-31CandidatePoC-in-GitHub · IAmNewbieZ/CVE-2021-44228★ 0IAmNewbieZ2022-02-04CandidatePoC-in-GitHub · FeryaelJustice/Log4ShellThis repository is for Log4j 2021 (CVE-2021-44228) Vulnerability demonstration and mitigation.★ 0FeryaelJustice2022-02-12CandidatePoC-in-GitHub · hotpotcookie/CVE-2021-44228-white-boxLog4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration★ 3hotpotcookie2022-02-12CandidatePoC-in-GitHub · s-retlaw/l4srsRust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)★ 0s-retlaw2022-02-16CandidatePoC-in-GitHub · Ananya-0306/Log-4j-scannerA fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228★ 3Ananya-03062022-02-24CandidatePoC-in-GitHub · paulvkitor/log4shellwithlog4j2_13_3Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.★ 0paulvkitor2022-03-09CandidatePoC-in-GitHub · MiguelM001/vulescanjndilookupHERRAMIENTA AUTOMATIZADA PARA LA DETECCION DE LA VULNERABILIDAD CVE-2021-44228★ 0MiguelM0012022-03-10CandidatePoC-in-GitHub · Jun-5heng/CVE-2021-44228Log4j2组件命令执行RCE / Code By:Jun_sheng★ 0Jun-5heng2022-03-11CandidatePoC-in-GitHub · vulnerable-apps/log4shell-honeypotJava application vulnerable to the CVE-2021-44228 (a.k.a log4shell) vulnerability★ 0vulnerable-apps2022-04-03CandidatePoC-in-GitHub · manishkanyal/log4j-scannerA Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046★ 1manishkanyal2022-04-17CandidatePoC-in-GitHub · TPower2112/Writing-Sample-1CVE-2021-44228 Log4j Summary★ 1TPower21122022-04-30CandidatePoC-in-GitHub · Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228★ 0Willian-2-0-0-12022-05-02CandidatePoC-in-GitHub · r3kind1e/Log4Shell-obfuscated-payloads-generatorGenerate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.★ 25r3kind1e2022-05-09CandidatePoC-in-GitHub · Phineas09/CVE-2021-44228Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc★ 0Phineas092022-05-13CandidatePoC-in-GitHub · hassaanahmad813/log4jCVE-2021-44228 vulnerability in Apache Log4j library★ 0hassaanahmad8132022-05-20CandidatePoC-in-GitHub · yuuki1967/CVE-2021-44228-Apache-Log4j-Rce★ 0yuuki19672022-05-25CandidatePoC-in-GitHub · moshuum/tf-log4j-aws-pocThis project files demostrate a proof-of-concept of log4j vulnerability (CVE-2021-44228) on AWS using Terraform Infrastructure-as-a-code means.★ 1moshuum2022-06-07CandidatePoC-in-GitHub · jaehnri/CVE-2021-44228Proof of concept of the Log4Shell vulnerability (CVE-2021-44228)★ 1jaehnri2022-06-08CandidatePoC-in-GitHub · ra890927/Log4Shell-CVE-2021-44228-DemoLog4Shell CVE-2021-44228 Demo★ 0ra8909272022-06-12CandidatePoC-in-GitHub · vino-theva/CVE-2021-44228Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell vulnerability and how it works, how it affects the victim, and how can this be mitigated★ 0vino-theva2022-08-02CandidatePoC-in-GitHub · tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228★ 0tharindudh2022-08-18CandidatePoC-in-GitHub · eurogig/jankybankSimple Java Front and Back end with bad log4j version featuring CVE-2021-44228★ 0eurogig2022-08-25CandidatePoC-in-GitHub · digital-dev/Log4j-CVE-2021-44228-RemediationThis powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.★ 0digital-dev2022-09-08CandidatePoC-in-GitHub · ocastel/log4j-shell-pocA Proof-Of-Concept for the CVE-2021-44228 vulnerability.★ 0ocastel2022-09-21CandidatePoC-in-GitHub · bcdunbar/CVE-2021-44228-pocCVE-2021-44228 POC / Example★ 1bcdunbar2022-09-21CandidatePoC-in-GitHub · srcporter/CVE-2021-44228DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"★ 1srcporter2022-11-08CandidatePoC-in-GitHub · sqsec/log4j2_CVE-2021-44228★ 0sqsec2022-12-30CandidatePoC-in-GitHub · demining/Log4j-VulnerabilityVulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can exploit vulnerable servers by connecting over any protocol, such as HTTPS, and sending a specially crafted string.★ 6demining2023-01-31CandidatePoC-in-GitHub · pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoCCVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.★ 1pierpaolosestito-dev2023-02-08CandidatePoC-in-GitHub · Sumitpathania03/LOG4J-CVE-2021-44228★ 0Sumitpathania032023-02-22CandidatePoC-in-GitHub · Sma-Das/Log4j-PoCAn educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft★ 3Sma-Das2023-03-14CandidatePoC-in-GitHub · 53buahapel/log4shell-vulnwebthis web is vulnerable against CVE-2021-44228★ 053buahapel2023-03-20CandidatePoC-in-GitHub · demonrvm/Log4ShellRemediationA vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105★ 1demonrvm2023-04-02CandidatePoC-in-GitHub · funcid/log4j-exploit-fork-bomb💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228★ 0funcid2023-04-15CandidatePoC-in-GitHub · MrHarshvardhan/PY-Log4j-RCE-ScannerUsing this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.★ 4MrHarshvardhan2023-06-29CandidatePoC-in-GitHub · Muhammad-Ali007/Log4j_CVE-2021-44228★ 0Muhammad-Ali0072023-07-19CandidatePoC-in-GitHub · Tai-e/CVE-2021-44228Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability★ 9Tai-e2023-10-06CandidatePoC-in-GitHub · roshanshibu/OdysseusA demo of the Log4Shell (CVE-2021-44228) vulnerability.★ 0roshanshibu2023-10-25CandidatePoC-in-GitHub · LucasPDiniz/CVE-2021-44228Log4j Vulnerability RCE - CVE-2021-44228★ 0LucasPDiniz2023-11-13CandidatePoC-in-GitHub · felixslama/log4shell-minecraft-demoLog4Shell (CVE-2021-44228) minecraft demo. Used for education fairs★ 0felixslama2023-11-21CandidatePoC-in-GitHub · ShlomiRex/log4shell_labCVE-2021-44228★ 0ShlomiRex2023-11-30CandidatePoC-in-GitHub · dcm2406/CVE-LabInstructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604★ 2dcm24062023-12-07CandidatePoC-in-GitHub · scabench/l4j-tp1jee web project with log4shell (CVE-2021-44228) vulnerability★ 0scabench2023-12-18CandidatePoC-in-GitHub · scabench/l4j-fp1jee web project with sanitised log4shell (CVE-2021-44228) vulnerability★ 0scabench2023-12-27CandidatePoC-in-GitHub · KtokKawu/l4s-vulnappThis is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).★ 0KtokKawu2024-03-15CandidatePoC-in-GitHub · sec13b/CVE-2021-44228-POCexploit CVE-2021-44228★ 1sec13b2024-03-23CandidatePoC-in-GitHub · KirkDJohnson/WiresharkDownloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the Log4J vulnerability (CVE-2021-44228). I examined teh amount of endpoints communicating with the server and knowing jnidi as a common in the vulnerbilty found it in clear text★ 3KirkDJohnson2024-03-26CandidatePoC-in-GitHub · YangHyperData/LOGJ4_PocShell_CVE-2021-44228★ 0YangHyperData2024-04-02CandidatePoC-in-GitHub · Hoanle396/CVE-2021-44228-demo★ 1Hoanle3962024-05-28CandidatePoC-in-GitHub · NikitaPark/Log4Shell-PoC-ApplicationLog4Shell (CVE-2021-44228) PoC Application★ 0NikitaPark2024-05-29CandidatePoC-in-GitHub · tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-EnvironmentObjective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.★ 3tadash102024-06-09CandidatePoC-in-GitHub · asd58584388/CVE-2021-44228CVE-2021-44228 vulnerability study★ 0asd585843882024-07-26CandidatePoC-in-GitHub · OtisSymbos/CVE-2021-44228-Log4Shell-★ 0OtisSymbos2024-09-11CandidatePoC-in-GitHub · safeer-accuknox/log4j-shell-pocLog4J exploit CVE-2021-44228★ 0safeer-accuknox2024-09-11CandidatePoC-in-GitHub · Carlos-Mesquita/TPASLog4ShellPoCProof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.★ 1Carlos-Mesquita2024-10-08CandidatePoC-in-GitHub · AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10★ 0AhmedMansour932024-11-10CandidatePoC-in-GitHub · Super-Binary/cve-2021-44228这是安徽大学 “漏洞分析实验”(大三秋冬)期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/★ 0Super-Binary2024-11-15CandidatePoC-in-GitHub · ZacharyZcR/CVE-2021-44228调试环境★ 0ZacharyZcR2025-01-20CandidatePoC-in-GitHub · qw3rtyou/CVE-2021-44228_dockernize★ 1qw3rtyou2025-02-04CandidatePoC-in-GitHub · yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.★ 0yadavmukesh2025-02-17CandidatePoC-in-GitHub · tpdlshdmlrkfmcla/Log4shellCVE-2021-44228★ 0tpdlshdmlrkfmcla2025-03-12CandidatePoC-in-GitHub · timothyjxhn/DeliberatelyVulnerableWebAppA Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.★ 0timothyjxhn2025-03-27CandidatePoC-in-GitHub · khaidtraivch/CVE-2021-44228-Log4Shell-Kiểm thử xâm nhập★ 0khaidtraivch2025-04-14CandidatePoC-in-GitHub · Fauzan-Aldi/Log4j-_VulnerabilityThe Web Is Vulnerable to CVE-2021-44228★ 0Fauzan-Aldi2025-05-08CandidatePoC-in-GitHub · SerpilRivas/log4shell-homework9Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident response, and a full screen recording.★ 0SerpilRivas2025-05-27CandidatePoC-in-GitHub · x1ongsec/CVE-2021-44228-Log4j-JNDICVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境★ 0x1ongsec2025-06-21CandidatePoC-in-GitHub · fabioeletto/hka-seminar-log4shellPraktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)★ 0fabioeletto2025-07-10CandidatePoC-in-GitHub · cuijiung/log4j-CVE-2021-44228★ 0cuijiung2025-07-11CandidatePoC-in-GitHub · Sorrence/CVE-2021-44228A simple Log4j PoC written in Go★ 0Sorrence2025-08-04CandidatePoC-in-GitHub · moften/Log4ShellLog4Shell CVE-2021-44228 PoC★ 0moften2025-09-09CandidatePoC-in-GitHub · KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-deviceThis repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.★ 0KamalideenAK2025-09-27CandidatePoC-in-GitHub · arabindadora/log4shellLog4Shell (CVE-2021-44228) PoC★ 0arabindadora2025-09-29CandidatePoC-in-GitHub · Mintimate/log4j2-bugmakerDemo of CVE-2021-44228 Log4Shell.★ 0Mintimate2025-10-28CandidatePoC-in-GitHub · mgueye3/Log4ShellThis repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.★ 0mgueye32025-11-16CandidatePoC-in-GitHub · PCMKUIT/CVE-2021-44228---Log4Shell-AnalysisTechnical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), and enterprise mitigation guidance.★ 0PCMKUIT2025-11-18CandidatePoC-in-GitHub · DrHaitham/Log4Shell-CVE-2021-44228Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.★ 0DrHaitham2025-12-05CandidatePoC-in-GitHub · Loliverte/Log4j-VulnerabilityÉtude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé et une proposition de mise à jour de PSSI. Pour un objectif de TP★ 0Loliverte2025-12-14CandidatePoC-in-GitHub · JoseMariaMicoli/Log4Shell-PoC**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sandbox to demonstrate JNDI injection, LDAP/RMI referral redirection, and remote code execution (RCE) via the Log4j 2 library.★ 0JoseMariaMicoli2026-01-14CandidatePoC-in-GitHub · agylabs/log4shell-remediationLog4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java applications★ 0agylabs2026-02-05CandidatePoC-in-GitHub · 0xBlackash/CVE-2021-44228CVE-2021-44228★ 00xBlackash2026-02-26CandidatePoC-in-GitHub · Codepumpking/log4shell-pocPOC for log4shll Vulnerablity (CVE-2021-44228)★ 0Codepumpking2026-03-15CandidatePoC-in-GitHub · wmohamed2033/wmohamed2033.github.ioCVE-2021-44228 Log4Shell — Penetration Test Writeup★ 0wmohamed20332026-03-17CandidatePoC-in-GitHub · Saru1718/THM---Solar-exploiting-Log-4jThis room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.★ 0Saru17182026-03-22CandidatePoC-in-GitHub · lathika-3006/Solar-exploiting-log-4jThis repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.★ 2lathika-30062026-03-22CandidatePoC-in-GitHub · Lavanya2085/solar-exploiting-log4jThis repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.★ 0Lavanya20852026-03-22CandidatePoC-in-GitHub · danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.★ 1danieljosmariyan72542026-03-26CandidatePoC-in-GitHub · jdormannn/SecureOps-LabPerformed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force authentication attempts and exploitation attempts targeting Log4Shell (CVE-2021-44228).★ 0jdormannn2026-04-09CandidatePoC-in-GitHub · joaovicdev/EXPLOIT-CVE-2021-44228PoC of CVE-2021-44228★ 0joaovicdev2026-04-10CandidatePoC-in-GitHub · pinaraltinok/Log4Shell-AttackMulti-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228★ 0pinaraltinok2026-04-22CandidatePoC-in-GitHub · kaleth4/CVE-2021-44228★ 0kaleth42026-04-27CandidatePoC-in-GitHub · tieupham267/log4shell-corazaLog4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.★ 0tieupham2672026-04-28CandidatePoC-in-GitHub · sajanapamuditha/Cyber-Attack-Simulation-Log4Shell (CVE-2021-44228)★ 0sajanapamuditha2026-05-02CandidatePoC-in-GitHub · neilc1964techned/craready-test-java-vulnsCRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs★ 0neilc1964techned2026-05-02CandidatePoC-in-GitHub · FacundoMfernandez/pentesting-obiobaPentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico★ 0FacundoMfernandez2026-05-05CandidatePoC-in-GitHub · vutiendat323/CVE-2021-44228_Log4Shell★ 0vutiendat3232026-05-12CandidatePoC-in-GitHub · aaronm-sysdig/log4j-vuln-demoIntentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)★ 0aaronm-sysdig2026-05-16CandidatePoC-in-GitHub · MAFO-sec/mi-laboratorio-log4shellLaboratorio automatizado Plug & Play en Docker para auditar y estudiar la vulnerabilidad Log4Shell (CVE-2021-44228)★ 0MAFO-sec2026-05-18CandidatePoC-in-GitHub · felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-★ 0felisha-elmer2026-05-23CandidatePoC-in-GitHub · jomjosh17/Log4Shell-CVE-2021-44228-★ 0jomjosh172026-05-30CandidatePoC-in-GitHub · C00LN3T/Log4ShellAuditorAn autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).★ 1C00LN3T2026-05-31CandidatePoC-in-GitHub · bhimsekhar/vulnerable-java-appSpring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target★ 0bhimsekhar2026-06-03CandidatePoC-in-GitHub · horrister/log4shell-cve-2021-44228★ 1horrister2026-06-04CandidatePoC-in-GitHub · hmxh123/Log4Shell-Vulnerability-ReplicationCVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)★ 0hmxh1232026-06-09CandidatePoC-in-GitHub · limxuan/ehir-vuln-enterprise-loginwebapp vulnerable to CVE-2021-44228★ 0limxuan2026-06-15CandidatePoC-in-GitHub · DAADAISMYLIFE/log4shell-labLog4Shell (CVE-2021-44228) 보안 실습 환경 - Log4j 2.14.1 취약 로그 수집 서버★ 0DAADAISMYLIFE2026-06-17CandidatePoC-in-GitHub · probablysecure/Triage-CVE-2021-44228-Log4Shell-Log4j-Goal is to triage well known attack and learn how security teams quickly respond.★ 0probablysecure2026-06-28CandidatePoC-in-GitHub · Ricardo354/homelab-CVE-2021-44228Log4j Vulnerability homelab★ 0Ricardo3542026-07-14CandidatePoC-in-GitHub · AstralJays/TraditionalJayIntentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)★ 0AstralJays2026-07-14CandidatePoC-in-GitHub · prmawyer/log4shell-vulnerable-appSpring Boot web application vulnerable to Log4Shell (CVE-2021-44228).★ 0prmawyer2026-07-16CandidatePoC-in-GitHub · arpitgupta369/log4shell-scannerLightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.★ 0arpitgupta3692026-07-18CandidatePoC-in-GitHub · razureink/cve-2021-44228-log4shell_rce_reproductionCVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE★ 1razureink2026-07-24CandidatePoC-in-GitHub · sfr0435122531-ui/-log4shell-labDocker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.★ 0sfr0435122531-ui2026-07-26CandidatePoC-in-GitHub · yili-soc/vm-homelab-log4shell-assessmentFull-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.★ 0yili-soc2026-08-01CandidatePoC-in-GitHub · sanasimran1403-jpg/log4shellLog4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.★ 0sanasimran1403-jpg2026-08-02CandidatePoC-in-GitHub · AhndreWalters/ProjectSecurity-HomelabHands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.★ 0AhndreWalters2026-08-07CandidatePoC-in-GitHub · Jiahong-Guan/log4j-shell-pocA Proof-Of-Concept for the CVE-2021-44228 vulnerability.★ 1Jiahong-Guan2026-08-09CandidatePoC-in-GitHub · Vaibhav91one/log4shell-cve-labLog4Shell CVE-2021-44228 vulnerable lab★ 0Vaibhav91one2026-08-30CandidatePoC-in-GitHub · 14free/log4j2-vuln-labCVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证★ 014free2026-09-01Candidate