References https://www.cnblogs.com/smileleooo/p/18133903 https://zhuanlan.zhihu.com/p/443689489 https://www.anquanke.com/post/id/262986 https://m.freebuf.com/articles/vuls/370458.html https://nic.syuct.edu.cn/info/1106/1664.htm https://bbs.kanxue.com/thread-270766-1.htm https://stack.chaitin.com/vuldb/detail/fcc63ba8-3aaa-4c64-bff5-98332c3d2f3f https://www.tencentcloud.com/zh/document/product/627/47897 https://ask.csdn.net/questions/8128657 https://www.secrss.com/articles/37160 https://github.com/H4ckTh3W0r1d/Apache_Log4j2_RCE https://xxwl.ncu.edu.cn/info/1022/4639.htm https://note.tonycrane.cc/sec/vulns/log4j/ https://info.sdju.edu.cn/2021/1210/c6627a91921/page.htm https://support.huaweicloud.com/bulletin-mrs/mrs_13_000003.html https://nosec.org/m/share/4917.html https://yinwc.github.io/2021/12/12/Log4j2%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://xxzx.fafu.edu.cn/_upload/article/files/9c/64/2abb99bb4fe7ac89cb6d9a2869d2/0838496c-1bdb-498f-baf4-2c26ae8f6c0e.pdf https://www.aliyun.com/sswb/1054612.html https://gitee.com/y_project/RuoYi/issues/I4MW2V?skip_mobile=true https://www.antiy.cn/Special/Apache_Log4j2/20211210.html https://tttang.com/archive/1378/ https://www.cmd8.com/post/421.html https://etnc.gduf.edu.cn/info/1034/1404.htm https://www.fujieace.com/java/apache-log4j2-perseverate.html https://wlaqxc.xaut.edu.cn/info/1007/1418.htm https://lonelysec.com/%E3%80%90%E6%BC%8F%E6%B4%9E%E9%A0%90%E8%AD%A6%E3%80%91apache-log4j-%E9%81%A0%E7%AB%AF%E7%A8%8B%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://developer.aliyun.com/article/888688 https://www.linkedin.com/posts/oligo-security_log4shell-applicationsecurity-cloudsecurity-activity-7409255197589393410-lRnC https://attackerkb.com/topics/in9sPR2Bzt/cve-2021-44228-log4shell https://github.com/JoseMariaMicoli/Log4Shell-PoC https://www.academia.edu/146240680/Systematic_Reconstruction_of_the_Log4Shell_CVE_2021_44228_Exploit_Chain
Related VulnerabilitiesPoCapache-livy-logs: Apache Livy - Logs ExposedApache Log4j2 远程代码执行漏洞(CVE-2021-44228)PoCCVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code ExecutionPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposureApache IoTDB 认证绕过与远程代码执行漏洞PoCCVE-2025-68493: Apache Struts XWork - XML External Entity InjectionPoCCVE-2024-42323: Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code ExecutionPoCCVE-2025-54988: Apache Tika - XXE InjectionPoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default CredentialsPoCCVE-2026-50229: Apache Tomcat - Cross-Site ScriptingApache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-5562)Apache Druid /proxy/coordinator@ 服务器端请求伪造漏洞(CVE-2025-27888)