<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Log4J exploit and VM parameter log4j2.formatMsgNoLookups</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121296261" />
  <subtitle>Log4J exploit and VM parameter log4j2.formatMsgNoLookups</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121296261</id>
  <updated>2026-04-06T18:11:29Z</updated>
  <dc:date>2026-04-06T18:11:29Z</dc:date>
  <entry>
    <title>RE: RE: Log4J exploit and VM parameter log4j2.formatMsgNoLookups</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121297650" />
    <author>
      <name>Andre Albert</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121297650</id>
    <updated>2021-12-14T14:53:27Z</updated>
    <published>2021-12-14T14:53:27Z</published>
    <summary type="html">&lt;p&gt;Many thanks Tomas for clarification on this.&lt;/p&gt;
&lt;p&gt;Best regards Andre&lt;/p&gt;</summary>
    <dc:creator>Andre Albert</dc:creator>
    <dc:date>2021-12-14T14:53:27Z</dc:date>
  </entry>
  <entry>
    <title>RE: Log4J exploit and VM parameter log4j2.formatMsgNoLookups</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296345" />
    <author>
      <name>Tomáš Polešovský</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296345</id>
    <updated>2021-12-14T14:52:33Z</updated>
    <published>2021-12-13T20:38:16Z</published>
    <summary type="html">&lt;p&gt;Hello Andre,&lt;/p&gt;
&lt;p&gt;I just tried and any of them works and protects:&lt;/p&gt;
&lt;pre&gt;
-DLog4j2.formatMsgNoLookups=true&lt;/pre&gt;
&lt;pre&gt;
-Dlog4j2.formatMsgNoLookups=true&lt;/pre&gt;
&lt;p&gt;Log4j has a special lookups tables ... &lt;a href="https://github.com/apache/logging-log4j2/blob/50979afd30cb575ba743c25847b62f52414b1d3a/log4j-api/src/main/java/org/apache/logging/log4j/util/PropertiesUtil.java#L482-L498"&gt;https://github.com/apache/logging-log4j2/blob/50979afd30cb575ba743c25847b62f52414b1d3a/log4j-api/src/main/java/org/apache/logging/log4j/util/PropertiesUtil.java#L482-L498&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>Tomáš Polešovský</dc:creator>
    <dc:date>2021-12-13T20:38:16Z</dc:date>
  </entry>
  <entry>
    <title>Log4J exploit and VM parameter log4j2.formatMsgNoLookups</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296260" />
    <author>
      <name>Andre Albert</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121296260</id>
    <updated>2021-12-13T18:35:36Z</updated>
    <published>2021-12-13T18:35:36Z</published>
    <summary type="html">&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Liferay wrote an article about the log4j eploit
  (https://help.liferay.com/hc/en-us/articles/4416190497805) and one
  statement is that setting the VM Launch parameter &lt;/p&gt;
&lt;pre&gt;
-DLog4j2.formatMsgNoLookups=true&lt;/pre&gt;
&lt;p&gt;will fix it.&lt;/p&gt;
&lt;p&gt;Is it save to have it with an uppercased L because on the web, it is
  said that &lt;/p&gt;
&lt;pre&gt;
-Dlog4j2.formatMsgNoLookups=true&lt;/pre&gt;
&lt;p&gt;will fix it. As far as i know, System parameters are case sensitive.
  So it save, or should i rather use the lowercase log4j2.formatMsgNoLookups?&lt;/p&gt;</summary>
    <dc:creator>Andre Albert</dc:creator>
    <dc:date>2021-12-13T18:35:36Z</dc:date>
  </entry>
</feed>
