A new variant of the attack on Log4j 2 allows bypassing the added protection.
Another vulnerability (CVE-2021-45046) has been discovered in the JNDI lookup implementation within the Log4j 2 library, appearing despite the fixes added in release 2.15 and regardless of the use of the 'log4j2.noFormatMsgLookup' configuration for protection. The issue poses a danger mainly for older versions of Log4j 2, protected by the 'noFormatMsgLookup' flag, as it allows for bypassing the protections against the previous vulnerability (Log4Shell, CVE-2021-44228), […]
