ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

On the Log4j Vulnerability

criticalVulnerabilityimportance 55
Full article148 words · extracted from schneier.com · click to collapse

It’s serious:

The range of impacts is so broad because of the nature of the vulnerability itself. Developers use logging frameworks to keep track of what happens in a given application. To exploit Log4Shell, an attacker only needs to get the system to log a strategically crafted string of code. From there they can load arbitrary code on the targeted server and install malware or launch other attacks. Notably, hackers can introduce the snippet in seemingly benign ways, like by sending the string in an email or setting it as an account username.

Threat advisory from Cisco. Cloudflare found it in the wild before it was disclosed. CISA is very concerned, saying that hundreds of millions of devices are likely affected.

Tags: Apache, vulnerabilities, zero-day

Posted on December 14, 2021 at 9:55 AM56 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/12/on-the-log4j-vulnerability.html