Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation

Discussion in 'other security issues & news' started by ronjor, Dec 10, 2021.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,911
    Location:
    Texas
    Original release date: December 10, 2021
     
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Global race to patch critical computer bug in open source software used by Apache servers

    Security experts around the world raced Friday to patch one of the worst computer vulnerabilities discovered in years, a critical flaw in open-source code widely used across industry and government in cloud services and enterprise software.

    'I’d be hard-pressed to think of a company that’s not at risk,' said Joe Sullivan, chief security officer for Cloudflare...

    The vulnerability, dubbed ‘Log4Shell,’ was rated 10 on a scale of one to 10...Anyone who wants to exploit it can get full access to an unpatched machine...

    'The internet’s on fire right now. People are scrambling to patch and there are script kiddies and all kinds of people scrambling to exploit it,' said Adam Meyers, senior vice president of intelligence at the cybersecurity firm Crowdstrike . 'In the last 12 hours it has been fully weaponized.'..."

    https://www.marketwatch.com/story/g...-apache-servers-01639166970?mod=mw_latestnews
     
  3. longshots

    longshots Registered Member

    Joined:
    Oct 20, 2017
    Posts:
    537
    Location:
    Australia
  4. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    It might be misleading. Yes, Apache Log4j 2 is under the umbrella of The Apache Software Foundation. Yet it has nothing to do with Apache HTTP Server.
     
  5. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/
    https://spring.io/blog/2021/12/10/log4j2-vulnerability-and-spring-boot
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,911
    Location:
    Texas
  8. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,911
    Location:
    Texas
    CISA Creates Webpage for Apache Log4j Vulnerability CVE-2021-44228
    .
     
  9. IvoShoen

    IvoShoen Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    849
  10. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16
    https://www.theregister.com/2021/12/14/apache_log4j_2_16_jndi_disabled/
     
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Brand-New Log4Shell Attack Vector Threatens Local Hosts
    https://threatpost.com/new-log4shell-attack-vector-local-hosts/177128/
     
  12. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Upgraded to log4j 2.16? Surprise, there's a 2.17 fixing DoS
    https://www.bleepingcomputer.com/ne...o-log4j-216-surprise-theres-a-217-fixing-dos/
     
  13. guest

    guest Guest

    Apache Log4j allows insecure JNDI lookups
    December 15, 2021 (Updated: December 20, 2021)
     
  14. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,905
    Location:
    U.S.A.
     
  15. guest

    guest Guest

    Mitigating Log4Shell and Other Log4j-Related Vulnerabilities
    Alert (AA21-356A)
    December 22, 2021
     
  16. guest

    guest Guest

    CISA releases Apache Log4j scanner to find vulnerable apps
    December 22, 2021
     
  17. guest

    guest Guest

    NVIDIA discloses applications impacted by Log4j vulnerability
    December 22, 2021
    NVIDIA: Security Notice: NVIDIA Response to Log4j Vulnerabilities - December 2021
     
  18. guest

    guest Guest

    Belgian Ministry of Defense affected by Log4j?
    December 21, 2021
     
  19. guest

    guest Guest

    Bug bounty platforms handling thousands of Log4j vulnerability reports
    Leading platforms report back from the front line as vendors grapple with landmark bug
    December 22, 2021
     
  20. guest

    guest Guest

    Beijing punishes Alibaba for not reporting Log4j loophole fast enough
    December 22, 2021
     
  21. guest

    guest Guest

    Log4j 2.17.1 out now, fixes new remote code execution bug
    December 28, 2021
     
  22. guest

    guest Guest

    Microsoft Sees Rampant Log4j Exploit Attempts, Testing
    January 4, 2022
     
  23. guest

    guest Guest

    FTC warns companies to secure consumer data from Log4J attacks
    January 4, 2022
    FTC: FTC warns companies to remediate Log4j security vulnerability
     
  24. guest

    guest Guest

    ICS Vendors Respond to Log4j Vulnerabilities
    January 5, 2022
     
  25. guest

    guest Guest

    NHS warns of hackers exploiting Log4Shell in VMware Horizon
    January 7, 2022
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.