A vulnerability in a widely used logging library (Log4j) has become a full-blown security meltdown, affecting digital systems across the internet. Hackers are already attempting to exploit it, but even as fixes emerge, researchers warn that the flaw could have serious repercussions worldwide.
See: https://www.wired.com/story/log4j-flaw-hacking-internet/
Please help us to address customers question if / where Vertica use Log4j?
Known Mitigations
From: https://www.darkreading.com/dr-tech/what-to-do-while-waiting-for-the-log4ju-updates
Update to the latest version of Java, as it will prevent loading a remote codebase using LDAP.
“The current exploitation mechanism is blocked by the latest version of Java, which sets com.sun.jndi.object.trustURLCodebase to true.
If Log4j cannot be updated, setting the log4j2.formatMsgNoLookups parameter to true when starting the Java Virtual Machine makes the vulnerability not exploitable, Apache says in its advisory. The command-line option is -Dlog4j.formatMsgNoLookups=true . Setting the JVM flag (log4j2.formatMsgNoLookups=true) in a component.properties file on the classpath also prevents lookups in log event messages.
Apache also suggests manually removing the JndiLookup class from the classpath (zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class) to protect against remote code execution. Removing the Jndi Manager class from will cause JndiContextSelector and JMSAppender to no longer function.
Specifying %m{nolookups} in the PatternLayout configuration prevents lookups in log event messages.
Another option is for the organization to control outbound traffic at the perimeter and block LDAP and RMI traffic, if possible.