Apache’s Fix for Log4Shell Can Lead to DoS Attacks
-
Not only is the jaw-dropping flaw in the Apache Log4j logging library ubiquitous; Apache’s blanket of a quickly baked patch for Log4Shell also has holes.
https://threatpost.com/apache-patch-log4shell-log4j-dos-attacks/177064/