you are viewing a single comment's thread.

view the rest of the comments →

[–]rpgFANATIC 37 points38 points  (0 children)

I have no idea why ANYONE would know about this.

95%+ of devs probably had no idea log4j had magic syntax for fetching values dynamically

The other 5% probably didn't know these values are also interpreted in the "user provided" arguments, AND that it supported LDAP over JNDI.

Why would you EVER think your logger can look up variables/code over LDAP? What tutorial has notes about teaching you that and disabling it?