top of page
  • WatchTower365

Security Advisory - CVE-2021-44228 | Apache Log4j utility Remote Code Execution Vulnerability

Updated: Oct 12, 2023


Apache Log4j

Description of Apache log4j 2

Apache log4j 2 is an open-source Java-based logging framework, which is leveraged within numerous Java applications around the world. Compared with the original log4j 1. X release, log4j 2 addressed is released, protecting us with the previous release and offering a plugin architecture for users.


On Aug. 5, 2015, log4j 2 became the mainstream version and all of the previous version log4j users were recommended to upgrade to log4j 2. Apache log4j 2 is widely used in many popular software applications, such as Apache Struts, ElasticSearch, Redis, and Kafka. On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache log4j 2 was identified as being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was effortless to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high-severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking out and exploiting unpatched systems.


List of Affected Software

  • Apache Struts

  • Apache Solr

  • Apache Druid

  • Apache Flink

  • ElasticSearch

  • Flume

  • Apache Dubbo

  • Logstash

  • Kafka

  • Spring-Boot-starter-log4j2

Affected Version

  • Apache Log4j 2.x <= 2.15.0-rc1

Apache Log4j

Mitigation

This vulnerability is actively being exploited and anyone using Log4j should update to version 2.15.0 as soon as possible. The latest version can already be found on the Log4j download page.


Note:
44 views0 comments
bottom of page