The Apache Software Foundation has published a summary report on the projects impacted by the critical vulnerability in Log4j 2, which allows arbitrary code execution on the server. The following Apache projects are at risk: Archiva, Druid, EventMesh, Flink, Fortress, Geode, Hive, JMeter, Jena, JSPWiki, OFBiz, Ozone, SkyWalking, Solr, Struts, TrafficControl, and Calcite Avatica. The vulnerability also affects GitHub products, including GitHub.com, GitHub Enterprise Cloud, and GitHub Enterprise Server.
Apache projects that are not affected by the vulnerability in Log4j 2: Apache Iceberg, Guacamole, Hadoop, Log4Net, Spark, Tomcat, ZooKeeper, and CloudStack.
Users of the affected packages are advised to urgently install the updates released for them, separately update the version of Log4j 2, or set the Log4j2.formatMsgNoLookups parameter to true (e.g., by adding the key '-DLog4j2.formatMsgNoLookups=True' at startup). To block the vulnerability on systems without direct access, the exploit vaccine Logout4Shell is suggested, which sets Java settings 'log4j2.formatMsgNoLookups = true', 'com.sun.jndi.rmi.object.trustURLCodebase = false', and 'com.sun.jndi.cosnaming.object.trustURLCodebase = false' to prevent further manifestation of the vulnerability on uncontrolled systems.
In recent days, there has been a significant increase in activity related to the exploitation of the vulnerability. For instance, Check Point has recorded at its trap around 100 exploitation attempts per minute, while Sophos reported the detection of a new botnet for cryptocurrency mining formed from systems with the unpatched vulnerability in Log4j 2. servers Additional:
The vulnerability is confirmed in many official Docker images, including images for Couchbase, Elasticsearch, Flink, Solr, Storm, etc.
- The vulnerability is present in the MongoDB Atlas Search product.
- The issue is manifested in various Cisco products, including the Cisco Webex Meetings Server, Cisco CX Cloud Agent, Cisco Advanced Web Security Reporting, Cisco Firepower Threat Defense (FTD), Cisco Identity Services Engine (ISE), Cisco CloudCenter, Cisco DNA Center, Cisco BroadWorks, etc.
- The issue is present in IBM WebSphere Application Server, as well as in the following Red Hat products: OpenShift, OpenShift Logging, OpenStack Platform, Integration Camel, CodeReady Studio, Data Grid, Fuse, and AMQ Streams.
- The issue is confirmed in Junos Space Network Management Platform, Northstar Controller/Planner, Paragon Insights/Pathfinder/Planner.
- Many products from Oracle, VMware, Broadcom, and Amazon are also vulnerable.
- Chrome update 96.0.4664.110 fixes critical and 0-day vulnerabilities.
Source: opennet.ru
