Site navigation

Apache Releases Another Patch in Wake of New Log4j Vulnerability

Graham Turner

,

New Log4j Vulnerability
A further vulnerability within Log4j was discovered on Tuesday and Apache has moved quickly to try and address it.

Cybersecurity experts were left scrambling to patch the first Log4j vulnerability, CVE-2021-44228, before news broke on Tuesday that a new vulnerability, CVE 2021-45046, was discovered.

A new patch has now been released that seeks to address the fact that patch 2.15.0 was ” “incomplete in certain non-default configurations,” according to the CVE description.

The new vulnerability circumventated the first patch as the incomplete configurations allowed attackers “to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack,” the CVE description says.

The CVE says the new patch Log4j 2.16.0 fixes the problem by removing support for message lookup patterns and disabling JNDI functionality by default. It also notes that the issue can be mitigated in prior releases by removing the JndiLookup class from the classpath.

The vulnerability affects all versions of Log4j from 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 (the latest patch), and is scored 3.7 out of 10 on the CVSS rating system.

This morning, Check Point Research (CPR) gave an example of how a real attack works through this vulnerability.

While most detected miners leveraged it for Linux-based crypto mining, Check Point researchers have now detected a cyberattack involving an undetected, first time, NET-based malware.

This specific attack today targeted five victims in the finance, banking, and software industries in the Israel, United States, South Korea, Switzerland and Cyprus. The server that contains the malicious files is located in the US and hosts multiple malicious files.

Such attacks (crypto oriented and less destructive) represent the early stages of large scale attacks (such as ransomware). It is sort of a “live trial” of the vulnerability and the potential of the damage it can cause in laying the groundwork to later perform a larger offensive.


Recommended


Once any type of malware is injected, it’s only a “question of time for a larger attack,” according to CPR.

Currently, CPR has tracked over 1,272,000 attempts to exploit the vulnerability, affecting over 44% of corporate networks globally.

Speaking about Log4j, Lotem Finkelstein, Head of Threat Intelligence at Check Point Software, said: “Unlike other major cyber attacks that involve one or limited number of software, Log4j is basically embedded in every Java based product or web service. It is very difficult to manually remediate it.

“Once an exploration was published (on Friday), scans of the internet ensued (to allocate surfaces which are vulnerable due to this incident). Those who won’t implement a protection are probably already scanned by malicious actors. Already, we’ve documented over 1,272,000 attacks, where over 44% of corporate networks globally have been targeted.

“This vulnerability, because of the complexity in patching it and easiness to exploit, will stay with us for years to come, unless companies and services take immediate action to prevent the attacks on their products by implementing a protection.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data