{"id":19443,"date":"2021-12-13T08:08:37","date_gmt":"2021-12-13T13:08:37","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19443"},"modified":"2021-12-13T08:08:37","modified_gmt":"2021-12-13T13:08:37","slug":"apache-log4j-2-vulnerability","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19443","title":{"rendered":"Apache Log4j 2 Vulnerability"},"content":{"rendered":"<p>You probably heard the news this weekend about the new critical remote code execution vulnerability affecting Apache log4j 2. A remote code execution vulnerability is an attack that can be launched from anywhere in the world, as long as an affected system is available remotely.<\/p>\n<p>Why is important? The vulnerability affects millions of devices, including web applications, IOT devices, etc. This means both personal and corporate devices could be vulnerable.<\/p>\n<h4>What should you do?<\/h4>\n<ul>\n<li><strong>Home<\/strong> &#8211; Look out for alerts from vendors that you purchased products from (e.g. Apple, Amazon, Google, etc.). If they recommend you update your devices, or if you are being prompted to, make sure to update them.<\/li>\n<li><strong>Office<\/strong> &#8211; You can also look out for alerts from vendors, but since there are so many more devices in the office setting, the easiest approach is to run a vulnerability scan or use one of the proof of concepts to test. (Another option in the office is a manual process and requires you taking an inventory of all the applications that have a web interface. Once identified, you can log in to each of them to determine if they are running Apache and Log4j.) Once the scan is complete and if anything is identified, determine if a patch is available by checking vendor websites, or take steps to limit exposure.<\/li>\n<\/ul>\n<h3>Some more specific things:<\/h3>\n<h4>How can I detect it?<\/h4>\n<ul>\n<li>Take a manual inventory of all applications running a web server and determine if Apache is installed. Next determine if Log4j is also installed<\/li>\n<li>Run a vulnerability scan using a commercial tool to determine if Log4j is present in the environment<\/li>\n<li>You can download and run an open source vulnerability scanning tool called <strong>grype,<\/strong> which can be found here: <a href=\"https:\/\/github.com\/anchore\/grype\">https:\/\/github.com\/anchore\/grype<\/a><\/li>\n<\/ul>\n<h4>How can I remediate it?<\/h4>\n<p>There are a few ways to remediate:<\/p>\n<ol>\n<li>Wait for the vendor to release a patch. (the most simplest).<\/li>\n<li>Rely on your Intrusion Detection\/Prevention provider to detect and block malicious traffic. This can also be done on certain firewalls.<\/li>\n<li>Download the latest Log4j mitigated version 2.15.0 from its <a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/download.html\">download page<\/a>\n<ol>\n<li>If you can&#8217;t upgrade, follow steps below:\n<ol>\n<li>If using version <strong>log4j2.x <\/strong>version <strong>&gt;=2.10<\/strong> and <strong>&lt;= 2.14.1<\/strong>, this behavior can be mitigated by either setting system property log4j2.formatMsgNoLookups or environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true.<\/li>\n<li class=\"pt-4\">If using version <strong>&gt;=2.0-beta9<\/strong> and <strong>&lt;=2.10.0<\/strong>, mitigation is to remove log4j\u2019s JndiLookup class from JVM\u2019s classpath as under:\n<pre><code class=\"language-java hljs \">zip -q -d log4j-core-*.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class<\/code><\/pre>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h4>Need help with detection?<\/h4>\n<p>If this sounds to cumbersome or you don&#8217;t know where to start, we can help. Reach out now and find out how we can scan your environment for this vulnerability and help you remediate it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You probably heard the news this weekend about the new critical remote code execution vulnerability affecting Apache log4j 2. A remote code execution vulnerability is an attack that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":19445,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[130,91,101,102,103,35,19],"tags":[131,82],"class_list":["post-19443","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apache","category-exploit","category-hackers","category-hedge-fund","category-investment-adviser","category-reverse-shell","category-vulnerability","tag-apache","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache Log4j 2 Vulnerability - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19443\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache Log4j 2 Vulnerability - Insights\" \/>\n<meta property=\"og:description\" content=\"You probably heard the news this weekend about the new critical remote code execution vulnerability affecting Apache log4j 2. A remote code execution vulnerability is an attack that [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19443\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-13T13:08:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"331\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Elteni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elteni\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443\"},\"author\":{\"name\":\"Elteni\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"headline\":\"Apache Log4j 2 Vulnerability\",\"datePublished\":\"2021-12-13T13:08:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443\"},\"wordCount\":462,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/log4j-vulnerability.png\",\"keywords\":[\"Apache\",\"Vulnerability\"],\"articleSection\":[\"Apache\",\"Exploit\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Reverse Shell\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443\",\"name\":\"Apache Log4j 2 Vulnerability - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/log4j-vulnerability.png\",\"datePublished\":\"2021-12-13T13:08:37+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/log4j-vulnerability.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2021\\\/12\\\/log4j-vulnerability.png\",\"width\":800,\"height\":331,\"caption\":\"log4j vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19443#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache Log4j 2 Vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\",\"name\":\"Elteni\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"Elteni\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache Log4j 2 Vulnerability - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19443","og_locale":"en_US","og_type":"article","og_title":"Apache Log4j 2 Vulnerability - Insights","og_description":"You probably heard the news this weekend about the new critical remote code execution vulnerability affecting Apache log4j 2. A remote code execution vulnerability is an attack that [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19443","og_site_name":"Insights","article_published_time":"2021-12-13T13:08:37+00:00","og_image":[{"width":800,"height":331,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png","type":"image\/png"}],"author":"Elteni","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Elteni","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19443#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443"},"author":{"name":"Elteni","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"headline":"Apache Log4j 2 Vulnerability","datePublished":"2021-12-13T13:08:37+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443"},"wordCount":462,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png","keywords":["Apache","Vulnerability"],"articleSection":["Apache","Exploit","Hackers","Hedge Fund","Investment Adviser","Reverse Shell","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19443","url":"https:\/\/www.elteni.com\/insights\/?p=19443","name":"Apache Log4j 2 Vulnerability - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png","datePublished":"2021-12-13T13:08:37+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19443#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19443"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19443#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2021\/12\/log4j-vulnerability.png","width":800,"height":331,"caption":"log4j vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19443#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"Apache Log4j 2 Vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075","name":"Elteni","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"Elteni"},"url":"https:\/\/www.elteni.com\/insights\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19443"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19443\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19445"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}