Critical Apache Log4j2 Remote Code Execution Vulnerability: Risks and Fixes

Google delays its office‑return plan and grants US staff a $1,600 bonus, while a severe Apache Log4j2 remote‑code‑execution flaw affecting many Java projects is disclosed with mitigation steps, and IntelliJ IDEA introduces built‑in audio‑video chat for collaborative coding.

21CTO
21CTO
21CTO
Critical Apache Log4j2 Remote Code Execution Vulnerability: Risks and Fixes

Google postpones office‑return plan and issues employee bonus

According to Reuters, Google will delay its return‑to‑office schedule and will give all U.S. employees a one‑time cash bonus of $1,600 (or equivalent), including long‑term staff and interns. The bonus is part of additional benefits such as home‑office allowances, though the total amount allocated for pandemic‑related support was not disclosed.

Critical Apache Log4j2 remote code execution vulnerability

Apache Log4j2, a widely used Java logging framework, received an emergency security update on December 9 to fix a remote code execution (RCE) vulnerability. The flaw can be exploited without special configuration by sending malicious requests that trigger recursive lookups, affecting components such as Apache Struts2, Solr, Druid, and Flink. The vulnerability is rated as severe.

Impacted versions include all 2.x releases; even the pre‑release 2.15.0‑rc1 is vulnerable.

Proof‑of‑concept and exploit code have been publicly released, and numerous attacks have been observed. The research institute “Ang Kai Pan Shi” has reproduced the issue.

Log4j2 vulnerability illustration
Log4j2 vulnerability illustration

Mitigation and recommendations

Upgrade Apache Log4j2 to the latest safe version 2.15.0‑rc2.

Update affected applications and components such as spring‑boot‑starter‑log4j2, Apache Struts2, Solr, Druid, and Flink.

Temporary work‑arounds:

Set JVM parameter -Dlog4j2.formatMsgNoLookups=true.

Set system environment variable FORMAT_MESSAGES_PATTERN_DISABLE_LOOKUPS=true.

Disable external network connections for the application.

IntelliJ IDEA adds built‑in audio‑video chat

IntelliJ IDEA now supports real‑time audio and video communication through the “Code With Me” plugin, enabling developers to start calls directly within the IDE. This feature is suitable for one‑on‑one meetings, small group sessions, pair programming, and collaborative debugging.

IntelliJ IDEA audio‑video chat interface
IntelliJ IDEA audio‑video chat interface

The functionality is currently in the Early Access Program, and interested users can test it.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

IntelliJ IDEARemote Code ExecutionJava SecurityAudio Video CollaborationGoogle Bonus
21CTO
Written by

21CTO

21CTO (21CTO.com) offers developers community, training, and services, making it your go‑to learning and service platform.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.