Apache Log4j·´ÐòÁл¯´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-24·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17571£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Log4j 1.2.27¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
Apache Log4jÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚJavaµÄ¿ªÔ´ÈÕÖ¾¼Í¼¹¤¾ß¡£
Apache Log4jÖÐÔ̺¬Ò»¸ö SocketServer À࣬ËüÈÝÒ×Êܵ½²»³ÉÐÅÊý¾Ý·´ÐòÁл¯µÄ¹¥»÷£¬µ±Ê¹Ó÷´ÐòÁл¯Ó×¹¤¾ß¼àÌý²»³ÉÐÅÍøÂçͨѶÁ÷ÒÔ»ñÈ¡ÈÕÖ¾Êý¾Ýʱ£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Apache¹Ù·½ÒÑÔÚа汾½¨¸´Á˸÷ì϶£¬Apache Log4j 1.2 °æ±¾¹Ù·½ÒÑÓÚ2015Äê8ÔÂÖÕ³¡ÊØ»¤£¬½¨ÒéÉý¼¶µ½ 2.8.2 »ò¸ü¸ß°æ±¾£ºhttp://logging.apache.org/log4j/2.x/index.html¡£
²Î¿¼Á´½Ó
https://www.openwall.com/lists/oss-security/2019/12/19/2


¾©¹«Íø°²±¸11010802024551ºÅ