Lars-Kristian Svenøy
12/10/2021, 5:02 PMMayank
Mayank
JDK versions greater than 6u211, 7u201, 8u191, and 11.0.1 are not affected by the LDAP attack vector. In these versions com.sun.jndi.ldap.object.trustURLCodebase is set to false meaning JNDI cannot load a remote codebase using LDAP.
Mayank
formatMsgNoLookups=true
as a w/a.Lars-Kristian Svenøy
12/10/2021, 6:04 PMPrashant Pandey
12/11/2021, 10:54 AMXiang Fu
openjdk version "11.0.13" 2021-10-19
OpenJDK Runtime Environment 18.9 (build 11.0.13+8)
OpenJDK 64-Bit Server VM 18.9 (build 11.0.13+8, mixed mode, sharing)
Mayank
Barna Lipics
12/13/2021, 4:10 PMMayank
Xiang Fu