Monday, June 1, 2026

Catastrophic Log4j security failure threatens global enterprise systems and web applications


A serious code execution vulnerability in Log4j allowed security experts to warn enterprise organizations and web applications that there could be catastrophic consequences.

The vulnerability is listed as CVE-2021-44228 in the Apache Log4j security vulnerability log, allowing remote attackers to control the affected system.

What is Log4j?

Log4j is an open source Apache logging system framework, which developers use to save records in applications.

This exploitation in the popular Java logging library leads to remote code execution (RCE). The attacker sends a string of malicious code that, when logged by Log4j, allows the attacker to load Java on the server and control it.

wired The report stated that the attacker used Minecraft’s chat feature to exploit the vulnerability on Friday afternoon.

Who is affected by Log4j security issues?

The problem is so serious that the U.S. Cybersecurity and Infrastructure Security Agency issued a notice December 10 This part explains:

“CISA encourages users and administrators to view Apache Log4j 2.15.0 announcement And upgrade to Log4j 2.15.0 or apply the recommended mitigation measures immediately. “

advertise

Keep reading below

The log cited above classifies the severity of the problem as “critical” and describes it as:

“Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters cannot prevent attackers from controlling LDAP and other JNDI-related endpoints.

When message search and replace is enabled, an attacker who can control log messages or log message parameters can execute arbitrary code loaded from the LDAP server. “

Marcus Hutchins from MalwareTech.com Warning iCloud, Steam and Minecraft have all been confirmed to have vulnerabilities:

LunaSec CEO Free Wortley wrote on December 9RCE zero day‘The blog post said, “Anyone who uses Apache Struts can be attacked.”

He also said, “Given the ubiquity of the library, the impact of exploits (full server control) and the ease of exploitation, the impact of this vulnerability is very serious.”

advertise

Keep reading below

CERT, Austrian Computer Emergency Response Team, Issued a warning It was pointed out on Friday that the affected include:

“All Apache log4j versions from 2.0 to 2.14.1 and all frameworks that use these versions (such as Apache Struts2, Apache Solr, Apache Druid, Apache Flink, etc.).

According to the security company LunaSec, JDK versions 6u211, 7u201, 8u191, and 11.0.1 are not affected in the default configuration because this does not allow remote code libraries to be loaded.

However, if the option com.sun.jndi.ldap.object.trustURLCodebaseYes trueSet to, the attack is still possible. “

Rob Joyce, Director of Cyber ​​Security, National Security Agency, Tweet on friday “Because of being widely included in the software framework, even NSA’s GHIDRA, the log4j vulnerability is a major exploit threat.

Security expert advice against Log4j vulnerabilities

Kevin Beaumont warned that even if you have upgraded to log4j-2.15.0-rc1, there is a bypass:

Marcus Hutchins from MalwareTech.com Provide solutions for those who cannot upgrade Log4j:

Matthew Prince, co-founder and CEO of Cloudflare Announced on friday:

We have made up our mind #Log4J Too bad, we will try to provide at least some protection for everyone Cloud flare Default customers, even free customers without our WAF. We are now studying how to do this safely. “

Chris Wysopal, co-founder and CTO of Veracode, recommends upgrading to at least Java 8:

advertise

Keep reading below

He also warned, “Maybe only 5% of applications still use Java 7, but this is the long tail that will be exploited in the coming months. Don’t have one of these in your organization.”

Determining which applications in your organization use Log4j should be a key task.


Featured image: Shutterstock/solarseven





Source link

Related articles

Most Popular Baby Names 2024: Top Picks

Join us as we explore the captivating world of the most popular baby names for 2024! Which name will you choose...

Most Popular Baby Names 2024: Top Picks

Join us as we explore the captivating world of the most popular baby names for 2024! Which name will you choose...

How to Settle a Colic Baby: Proven Tips

Eager to discover effective ways to calm your colicky baby? From soothing techniques to critical consultation cues, let's explore what...

What Is Colic in Babies: Key Facts Revealed

Understanding what colic in babies truly entails can be a challenge for many parents. As the evening wears on, and the baby's cries reach a crescendo, an urgent question looms in the air: what now?

The 7 Best Ways to Gain Popularity

Online searches are often not the starting point...
spot_imgspot_img