Skip to main content
Question

Security alert! Do we use Log4j Java library?

  • December 11, 2021
  • 2 replies
  • 9 views

mosheg
Forum|alt.badge.img+2
  • Participating Frequently

A vulnerability in a widely used logging library (Log4j) has become a full-blown security meltdown, affecting digital systems across the internet. Hackers are already attempting to exploit it, but even as fixes emerge, researchers warn that the flaw could have serious repercussions worldwide.
See: https://www.wired.com/story/log4j-flaw-hacking-internet/

Please help us to address customers question if / where Vertica use Log4j?

Known Mitigations
From: https://www.darkreading.com/dr-tech/what-to-do-while-waiting-for-the-log4ju-updates
Update to the latest version of Java, as it will prevent loading a remote codebase using LDAP.
“The current exploitation mechanism is blocked by the latest version of Java, which sets com.sun.jndi.object.trustURLCodebase to true.

If Log4j cannot be updated, setting the log4j2.formatMsgNoLookups parameter to true when starting the Java Virtual Machine makes the vulnerability not exploitable, Apache says in its advisory. The command-line option is -Dlog4j.formatMsgNoLookups=true . Setting the JVM flag (log4j2.formatMsgNoLookups=true) in a component.properties file on the classpath also prevents lookups in log event messages.

Apache also suggests manually removing the JndiLookup class from the classpath (zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class) to protect against remote code execution. Removing the Jndi Manager class from will cause JndiContextSelector and JMSAppender to no longer function.

Specifying %m{nolookups} in the PatternLayout configuration prevents lookups in log event messages.

Another option is for the organization to control outbound traffic at the perimeter and block LDAP and RMI traffic, if possible.

2 replies

mosheg
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • December 13, 2021

It seems there was a typo in the statement in the forum, and it is fixed now.
The typo was in this statement:
zip -q -d WEB-INF/lib/log4j-core-.jar org/apache/logging/log4j/core/lookup/JndiLookup.class

Ask the customer to run this one.
zip -q -d WEB-INF/lib/log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class

Thank you Jawahar for sharing this.


mosheg
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • December 13, 2021