Log4j Blues

Started by deanwebb, December 16, 2021, 08:28:07 AM

Previous topic - Next topic

deanwebb

Well, I've had to move planned holiday PTO because of Log4j.  :'(

Just so everyone knows, version 2.15 fixes most things. Version 2.16 fixes all known vulnerabilities.

Lots of vendors impacted, too many for the CISA to fully track. Thankfully, the major operating systems don't run on java, so we don't have to rush out patches for all of Windows or MacOS or Linux platforms. All the same, this incident draws a line under any company's level of patch management.
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.


Dieselboy

Since you wrote that post, they released v 2.17 to fix another vulnerability that existed in 2.16 on 18th December.

Quote from: https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html
Apache has released log4j 2.17.0 to address the new vulnerability CVE-2021-45105. The vulnerability is the result of an infinite recursion resulting in denial of service. Recommendation is to upgrade to 2.17.0. Additional details of the vulnerability can be found below. This vulnerability is already detected with existing coverage.

Update your signatures...

QuoteUpdated Coverage: Cisco Talos has released additional coverage today including vSphere detection. New signatures released are SIDs: 58740-58742, 58801-58814. Additionally, Cisco Talos has released new and updated ClamAV signatures.






deanwebb

Yep. 2.17 is the one that fixes everything. Today. As of 8:30 AM, US Central Time. :smug:

:facepalm1:
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.