ืฉืœื™ืฉ ืžืคืจื•ื™ืงื˜ื™ Java ื”ืžื‘ื•ืกืกื™ื ืขืœ ืกืคืจื™ื™ืช Log4j ืžืžืฉื™ื›ื™ื ืœื”ืฉืชืžืฉ ื‘ื’ืจืกืื•ืช ืคื’ื™ืขื•ืช

Veracode ืคืจืกืžื” ืืช ื”ืชื•ืฆืื•ืช ืฉืœ ืžื—ืงืจ ืขืœ ื”ืจืœื•ื•ื ื˜ื™ื•ืช ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช ื‘ืกืคืจื™ื™ืช Log4j Java, ืฉื–ื•ื”ืชื” ื‘ืฉื ื” ืฉืขื‘ืจื” ื•ื‘ืฉื ื” ืฉืœืคื ื™ื”. ืœืื—ืจ ืžื—ืงืจ ืฉืœ 38278 ื™ื™ืฉื•ืžื™ื ื”ืžืฉืžืฉื™ื 3866 ืืจื’ื•ื ื™ื, ื—ื•ืงืจื™ Veracode ื’ื™ืœื• ืฉ-38% ืžื”ื ืžืฉืชืžืฉื™ื ื‘ื’ืจืกืื•ืช ืคื’ื™ืขื•ืช ืฉืœ Log4j. ื”ืกื™ื‘ื” ื”ืขื™ืงืจื™ืช ืœื”ืžืฉืš ื”ืฉื™ืžื•ืฉ ื‘ืงื•ื“ ืžื“ื•ืจ ืงื•ื“ื ื”ื™ื ื”ืฉื™ืœื•ื‘ ืฉืœ ืกืคืจื™ื•ืช ื™ืฉื ื•ืช ื‘ืคืจื•ื™ืงื˜ื™ื ืื• ื”ืขืžืœ ืฉื‘ืžืขื‘ืจ ืžืขื ืคื™ื ืœื ื ืชืžื›ื™ื ืœืขื ืคื™ื ื—ื“ืฉื™ื ื”ืชื•ืืžื™ื ืœืื—ื•ืจ (ืื ืœืฉืคื•ื˜ ืœืคื™ ื“ื•ื— ืงื•ื“ื ืฉืœ Veracode, 79% ืžื”ืกืคืจื™ื•ืช ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืขื‘ืจื• ืœืคืจื•ื™ืงื˜ ื”ืงื•ื“ ืœืขื•ืœื ืื™ื ื• ืžืขื•ื“ื›ืŸ ืœืื—ืจ ืžื›ืŸ).

ื™ืฉื ืŸ ืฉืœื•ืฉ ืงื˜ื’ื•ืจื™ื•ืช ืขื™ืงืจื™ื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื•ืช ื‘ื’ืจืกืื•ืช ืคื’ื™ืขื•ืช ืฉืœ Log4j:

  • 2.8% ืžื”ืืคืœื™ืงืฆื™ื•ืช ืžืžืฉื™ื›ื•ืช ืœื”ืฉืชืžืฉ ื‘ื’ืจืกืื•ืช Log4j ืž-2.0-beta9 ืขื“ 2.15.0, ื”ืžื›ื™ืœื•ืช ืืช ื”ืคื’ื™ืขื•ืช ืฉืœ Log4Shell (CVE-2021-44228).
  • 3.8% ืžื”ื™ื™ืฉื•ืžื™ื ืžืฉืชืžืฉื™ื ื‘ืžื”ื“ื•ืจืช Log4j2 2.17.0, ืืฉืจ ืžืชืงื ืช ืืช ื”ืคื’ื™ืขื•ืช ืฉืœ Log4Shell, ืืš ืžืฉืื™ืจื” ืืช ื”ืคื’ื™ืขื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง CVE-2021-44832 (RCE) ืœืœื ืชื™ืงื•ืŸ.
  • 32% ืžื”ื™ื™ืฉื•ืžื™ื ืžืฉืชืžืฉื™ื ื‘ืขื ืฃ Log4j2 1.2.x, ืฉื”ืชืžื™ื›ื” ื‘ื• ื”ืกืชื™ื™ืžื” ืขื•ื“ ื‘-2015. ืขื ืฃ ื–ื” ืžื•ืฉืคืข ืžืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช CVE-2022-23307, CVE-2022-23305 ื•-CVE-2022-23302, ืฉื–ื•ื”ื• ื‘ืฉื ืช 2022 7 ืฉื ื™ื ืœืื—ืจ ืกื™ื•ื ื”ืชื—ื–ื•ืงื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”