{"id":21970344,"url":"https://github.com/guerzon/log4shellpoc","last_synced_at":"2026-04-12T11:46:10.562Z","repository":{"id":104241652,"uuid":"438390351","full_name":"guerzon/log4shellpoc","owner":"guerzon","description":"Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)","archived":false,"fork":false,"pushed_at":"2021-12-17T23:47:41.000Z","size":855,"stargazers_count":1,"open_issues_count":0,"forks_count":1,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-03-22T22:43:03.506Z","etag":null,"topics":["jndi-exploit","log4j","log4j2","penetration-testing","proof-of-concept"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/guerzon.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-12-14T20:27:26.000Z","updated_at":"2023-02-21T10:56:02.000Z","dependencies_parsed_at":null,"dependency_job_id":"64597fe3-bfa9-405c-877c-e54c41a4fe76","html_url":"https://github.com/guerzon/log4shellpoc","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/guerzon/log4shellpoc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guerzon%2Flog4shellpoc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guerzon%2Flog4shellpoc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guerzon%2Flog4shellpoc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guerzon%2Flog4shellpoc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/guerzon","download_url":"https://codeload.github.com/guerzon/log4shellpoc/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guerzon%2Flog4shellpoc/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":269827822,"owners_count":24481578,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-11T02:00:10.019Z","response_time":75,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["jndi-exploit","log4j","log4j2","penetration-testing","proof-of-concept"],"created_at":"2024-11-29T14:38:48.937Z","updated_at":"2025-10-24T01:05:07.581Z","avatar_url":"https://github.com/guerzon.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"\n# Simple Spring Boot application vulnerable to CVE-2021-44228 (Log4Shell)\n\nThis proof-of-concept application for CVE-2021-44228 (a.k.a log4shell) is a part of my [writeup](https://www.pidnull.io/2021/12/17/CVE-2021-44228-log4j2-analysis-exploit-PoC.html). For the complete exploit details, refer to the writeup.\n\n## Instructions\n\nRun:\n\n```bash\ndocker run --rm -p 8080:8080 --name log4shell-poc-app ghcr.io/guerzon/log4shellpoc:latest\n```\n\nOr build and run:\n\n```bash\ndocker build . -t log4shellpoc\ndocker run --rm -p 8080:8080 --name log4shell-poc-app log4shellpoc\n```\n\n### Result\n\n![](screenshots/recording.gif)\n\n## Notes\n\nSpring Boot project inspired by: https://github.com/christophetd/log4shell-vulnerable-app/\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fguerzon%2Flog4shellpoc","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fguerzon%2Flog4shellpoc","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fguerzon%2Flog4shellpoc/lists"}