Vulnerability detected in Java logging library Apache Log4j can result in full server takeover. Security firm Cybereason says it has developed and released an urgent “vaccine” for the easily exploitable flaw. The fix just disables the vulnerability and allows users to remain protected while they assess and update their servers. The unauthenticated remote code execution vulnerability – classified as CVE-2021-44228, with a CVSS score of 10 – is actively being exploited in the wild.”]
Source: https://www.govinfosecurity.com/log4j-vaccine-released-for-exploited-apache-zero-day-a-18105

