漏洞描述 Log4j2 中默认支持 JNDI(Java Naming and DirectoryInterface),如果用户的日志内容可控,就可能触发远程加载恶意类并执行,造成 远程代码执行(RCE)。