ืขื“ื›ื•ืŸ Log4j 2.17.1 ืขื ืคื’ื™ืขื•ืช ื ื•ืกืคืช ืชื•ืงื ื”

ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืกืคืจื™ื™ืช Log4j 2.17.1, 2.3.2-rc1 ื•-2.12.4-rc1 ืคื•ืจืกืžื•, ืืฉืจ ืžืชืงื ื™ื ืคื’ื™ืขื•ืช ื ื•ืกืคืช (CVE-2021-44832). ืžื•ื–ื›ืจ ืฉื”ื‘ืขื™ื” ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง (RCE), ืืš ืžืกื•ืžื ืช ื›ืฉืคื™ืจ (CVSS Score 6.6) ื•ื‘ืขื™ืงืจ ืขื ื™ื™ืŸ ืชื™ืื•ืจื˜ื™ ื‘ืœื‘ื“, ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ื“ื•ืจืฉืช ืชื ืื™ื ืกืคืฆื™ืคื™ื™ื ืœื ื™ืฆื•ืœ - ื”ืชื•ืงืฃ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘- ืงื•ื‘ืฅ ื”ื”ื’ื“ืจื•ืช Log4j, ื›ืœื•ืžืจ. ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื‘ืขืœ ื’ื™ืฉื” ืœืžืขืจื›ืช ื”ืžื•ืชืงืคืช ื•ืกืžื›ื•ืช ืœืฉื ื•ืช ืืช ื”ืขืจืš ืฉืœ ืคืจืžื˜ืจ ื”ืชืฆื•ืจื” log4j2.configurationFile ืื• ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืงื‘ืฆื™ื ืงื™ื™ืžื™ื ืขื ื”ื’ื“ืจื•ืช ืจื™ืฉื•ื.

ื”ืžืชืงืคื” ืžืกืชื›ืžืช ื‘ื”ื’ื“ืจืช ืชืฆื•ืจื” ืžื‘ื•ืกืกืช JDBC Appender ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช ื”ืžืชื™ื™ื—ืกืช ืœ-JNDI URI ื—ื™ืฆื•ื ื™, ืฉืขืœ ืคื™ ื‘ืงืฉืชื• ื ื™ืชืŸ ืœื”ื—ื–ื™ืจ ืžื—ืœืงื” ืฉืœ Java ืœื‘ื™ืฆื•ืข. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, JDBC Appender ืื™ื ื• ืžื•ื’ื“ืจ ืœื˜ืคืœ ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉืื™ื ื Java, ื›ืœื•ืžืจ. ื‘ืœื™ ืœืฉื ื•ืช ืืช ื”ืชืฆื•ืจื”, ื”ื”ืชืงืคื” ื‘ืœืชื™ ืืคืฉืจื™ืช. ื‘ื ื•ืกืฃ, ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืจืง ืขืœ ื”-log4j-core JAR ื•ืื™ื ื” ืžืฉืคื™ืขื” ืขืœ ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-log4j-api JAR ืœืœื log4j-core. ...

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”