Log4j 2.17.1 update fixing another vulnerability

Corrective releases of the Log4j library 2.17.1, 2.3.2-rc1, and 2.12.4-rc1 have been published, addressing another vulnerability (CVE-2021-44832). It is noted that the issue allows for remote code execution (RCE), but is marked as low risk (CVSS Score 6.6) and mainly represents only a theoretical interest, as it requires specific conditions for exploitation — the attacker must be able to modify the Log4j configuration file, meaning they must have access to the targeted system and the authority to change the configuration parameter log4j2.configurationFile or make changes to existing logging configuration files.

The attack involves identifying the JDBC Appender configuration on the local system that references an external JNDI URI, which, when queried, could return a Java class for execution. By default, the JDBC Appender is not configured to handle protocols other than Java, meaning the attack is not possible without configuration changes. Furthermore, the issue only manifests in the log4j-core JAR file and does not affect applications using the log4j-api JAR without log4j-core. …

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster