ื ื“ืจื™ื˜ ืคื•ืŸ Java ืคึผืจืึทื“ื–ืฉืขืงืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ Log4j ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืคืึธืจื–ืขืฆืŸ ืฆื• ื ื•ืฆืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื•ื•ืขืจืกื™ืขืก

Veracode ื”ืื˜ ืคืืจืขืคื ื˜ืœืขื›ื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืคื•ืŸ ืึท ืœืขืจื ืขืŸ ืคื•ืŸ ื“ื™ ืฉื™ื™ื›ื•ืช ืคื•ืŸ ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ Log4j Java ื‘ื™ื‘ืœื™ืึธื˜ืขืง, ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืœืขืฆื˜ืข ื™ืึธืจ ืื•ืŸ ื“ื™ ื™ืึธืจ ืคืจื™ืขืจ. ื ืึธืš ืœืขืจื ืขืŸ 38278 ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื’ืขื ื™ืฆื˜ ื“ื•ืจืš 3866 ืึธืจื’ืึทื ืึทื–ื™ื™ืฉืึทื ื–, ื•ื•ืขืจืึทืงืึธื“ ืจื™ืกืขืจื˜ืฉืขืจื– ื’ืขืคึฟื•ื ืขืŸ ืึทื– 38% ืคื•ืŸ ื–ื™ื™ ื ื•ืฆืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ Log4j. ื“ื™ ื”ื•ื™ืคึผื˜ ืกื™ื‘ื” ืคึฟืึทืจ ืคืึธืจื–ืขืฆืŸ ืฆื• ื ื•ืฆืŸ ืœืขื’ืึทื˜ ืงืึธื“ ืื™ื– ื“ื™ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืคื•ืŸ ืึทืœื˜ ืœื™ื™ื‘ืจืขืจื™ื– ืื™ืŸ ืคึผืจืึทื“ื–ืฉืขืงืก ืึธื“ืขืจ ื“ื™ ืœืึทื‘ืึธืจื™ืึทืกื ืึทืก ืคื•ืŸ ืžื™ื’ืจื™ื™ื˜ื™ื ื’ ืคื•ืŸ ืึทื ืกืึทืคึผืึธืจื˜ื™ื“ ืฆื•ื•ื™ื™ื’ืŸ ืฆื• ื ื™ื™ึทืข ืฆื•ื•ื™ื™ื’ืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืฆื•ืจื™ืง ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ (ืฆื• ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ืึท ืคืจื™ืขืจื“ื™ืงืŸ ื•ื•ืขืจืึทืงืึธื“ ื‘ืึทืจื™ื›ื˜, 79% ืคื•ืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืœื™ื™ื‘ืจืขืจื™ื– ืžื™ื’ืจื™ื™ื˜ื™ื“ ืื™ืŸ ืคึผืจื•ื™ืขืงื˜ ืงืึธื“ ื–ืขื ืขืŸ ืงื™ื™ื ืžืึธืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜).

ืขืก ื–ืขื ืขืŸ ื“ืจื™ื™ ื”ื•ื™ืคึผื˜ ืงืึทื˜ืขื’ืึธืจื™ืขืก ืคื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื ื•ืฆืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ Log4j:

  • 2.8% ืคื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืคืึธืจื–ืขืฆืŸ ืฆื• ื ื•ืฆืŸ Log4j ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ 2.0-beta9 ืฆื• 2.15.0, ื•ื•ืึธืก ืึทื ื˜ื”ืึทืœื˜ืŸ ื“ื™ Log4Shell ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2021-44228).
  • 3.8% ืคื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื ื•ืฆืŸ ื“ื™ Log4j2 2.17.0 ืžืขืœื“ื•ื ื’, ื•ื•ืึธืก ืคื™ืงืกื™ื– ื“ื™ Log4Shell ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืึธื‘ืขืจ ืœืึธื–ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ื“ื™ CVE-2021-44832 ื•ื•ื™ื™ึทื˜ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ (RCE) ืึทื ืคื™ืงืกื˜.
  • 32% ืคื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื ื•ืฆืŸ ื“ื™ Log4j2 1.2.x ืฆื•ื•ื™ื™ึทื’, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื•ื•ืึธืก ืื™ื– ื’ืขืขื ื“ื™ืงื˜ ืฆื•ืจื™ืง ืื™ืŸ 2015. ื“ืขืจ ืฆื•ื•ื™ื™ึทื’ ืื™ื– ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2022-23307, CVE-2022-23305 ืื•ืŸ CVE-2022-23302, ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ 2022 7 ื™ืึธืจ ื ืึธืš ื“ืขื ืกื•ืฃ ืคื•ืŸ ื•ื™ืฉืึทืœื˜.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster