Basically, Log4j is an Apache package (written in Java) which does logging. A lot of recent versions have a vulnerability (CVE-2021-44228, aka Log4Shell) which allows RCE (Remote Code Execution). Basically, if you send a particular string to the website, you can launch code; you can do that from the login screen, so this attack doesn't require authentication. It has a base CVSS v3 score of 10, which is the highest possible score.
The good news is that Log4j has a new version out which fixes the problem, so you just need to install the patch.
The bad news is that you wouldn't install something like this directly; it will be a module buried inside another application. E.g. VMware have put out a security advisory with a list of all their affected products:
VMSA-2021-0028.1 (vmware.com)
At the time of posting, there's no fixed version for any of them, but they've given workaround instructions for some of the products.
Some people have argued that this demonstrates the need for SBOM (Software Build Of Materials). The idea is that each application would include a list of all the modules etc. that it uses, then you can search through the list in a situation like this rather than having to hunt around all the vendors websites. However, there's still an argument for testing each device/website to check whether it's affected.
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: What no atW/SE DOOM thread yet?
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "What no atW/SE DOOM thread yet?"
Collapse
-
Yeah I read that earlier today.
I expected someone else to start a thread.
Leave a comment:
-
What no atW/SE DOOM thread yet?
What's this Log4Shell vulnerability about? Spoke to my son who works in IT in the city and calamitous apparently.
https://www.wired.com/story/log4j-fl...king-internet/Tags: None
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- ‘Subdued’ IT contractor jobs market took third tumble in a row in August Today 08:07
- Are CVs medieval or just being misused? Yesterday 05:05
- Are CVs medieval or just being misused? Sep 23 21:05
- IR35: Mutuality Of Obligations — updated for 2025/26 Sep 23 05:22
- Only proactive IT contractors can survive recruitment firm closures Sep 22 07:32
- How should a creditors’ meeting ideally pan out for unpaid suppliers? Sep 19 07:16
- How should a creditors’ meeting ideally pan out for unpaid suppliers? Sep 18 21:16
- IR35: Substitution — updated for 2025/26 Sep 18 05:45
- Payment request to bust recruitment agency — free template Sep 16 21:04
- Why licensing umbrella companies must be key to 2027’s regulation Sep 16 13:55
Leave a comment: