hotpatch-for-apache-log4j2
hotpatch-for-apache-log4j2 copied to clipboard
No protection from combined attack with CVE-2021-45105
With CVE-2021-45105 a malicious user can cause a DoS which in most scenarios will lead to JVM restart.
After restart there's a time window when an attack against CVE-2021-45046 or CVE-2021-44228 could be launched before the agent has attached to the JVM process.
Would it be possible to extend this solution to cover this scenario as well?