• Login
Fintedex — Business, Fincance & Investment News
  • Contact
  • Submit a News Releases
No Result
View All Result
  • Contact
  • Submit a News Releases
No Result
View All Result
Fintedex — Business, Fincance & Investment News
No Result
View All Result
Home Technology

Yet another Log4j patch hoovers up new remote code execution bug

Timothy Wilson by Timothy Wilson
29.12.2021
in Technology
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Apache has released yet another patch for the now-infamous Log4j utility, which delivers a fix for a new remote code execution vulnerability.

The logging utility has been the center of attention in the cybersecurity community for much of December, after a major vulnerability was discovered that enabled malicious actors with very limited knowledge to run scripts remotely.

This gaping hole has since been patched, but the newer version of the logger came with flaws of its own, albeit not as dangerous as the original. Soon after that vulnerability was patched, yet another issue was discovered. 

With Log4j version 2.17.1., the latest vulnerability (tracked as CVE-2021-44832), has now been fixed. All users have been urged to prioritize the update.

Another Log4j patch

The latest vulnerability is classified as a remote code execution flaw, stemming from the lack of extra controls on JDNI access in Log4j. As BleepingComputer reports, the flaw is rated “Moderate” in severity, and has been assigned a score of 6.6/10 as per the Common Vulnerability Scoring System (CVSS). 

“JDBC Appender should use JndiManager when accessing JNDI. JNDI access should be controlled via a system property,” the flaw description explains.

“Related to CVE-2021-44832 where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code.”

The original Log4j vulnerability, tracked as CVE-2021-44228, was given the nickname Log4Shell. It allowed crooks to run virtually any code remotely and, given the widespread use of Log4j, quickly became a nightmare for corporations and government organizations around the world.

Jen Easterly, Director of the US Cybersecurity and Infrastructure Security Agency (CISA), described it as “one of the most serious” flaws she’s seen in her entire career, “if not the most serious”.

  • You might also want to check out our list of the best antivirus solutions around today

Via BleepingComputer


Previous Post

The Book of Boba Fett episode 1: a delightful return to Star Wars’ criminal underworld

Next Post

New research counts the costs of the Sino-American trade war

Related Posts

Some Windows updates might actually hurt your security
Technology

Some Windows updates might actually hurt your security

by Timothy Wilson
16.05.2022
Tech Moves: Longtime Microsoft leader James Phillips leaves Stripe; and more
Technology

Tech Moves: Longtime Microsoft leader James Phillips leaves Stripe; and more

by Timothy Wilson
16.05.2022
It looks like Apple WWDC 2022 will be in-person after all – for some
Technology

It looks like Apple WWDC 2022 will be in-person after all – for some

by Timothy Wilson
16.05.2022
Save up to $700 during Nolah Mattress’ Memorial Day Sale
Technology

Save up to $700 during Nolah Mattress’ Memorial Day Sale

by Timothy Wilson
16.05.2022
Report: Apple bringing USB-C to the iPhone but not the iPhone 14
Technology

Report: Apple bringing USB-C to the iPhone but not the iPhone 14

by Timothy Wilson
16.05.2022
Next Post

New research counts the costs of the Sino-American trade war

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Premium Content

7 women-centric Indian movies to watch on OTT platforms for women’s day

07.03.2022

: The Powerball jackpot now stands at $441 million, but this recovered lottery addict won’t be among those buying a ticket

28.12.2021

Need to Know: Here’s a simple way to fade big tech and play a broader economic recovery

31.12.2021

Browse by Category

  • Business
  • Finance
  • Stock Market
  • Technology
  • Без рубрики

Browse by Tags

Europe Oleg Volin Russia Ukraine

Fintedex delivers real-time news about the financial industry: feature stories, industry developments, opinions plus the latest on people and trends.

Categories

  • Business
  • Finance
  • Stock Market
  • Technology
  • Без рубрики

Browse by Tag

Europe Oleg Volin Russia Ukraine

Recent Posts

  • The Location Guide, Filmmakers for Ukraine and EUFCN join forces for fundraiser at Cannes 2022
  • Free exchange: The world needs a new economic motor. Could India fit the bill?
  • Buttonwood: Why Italy’s borrowing costs are surging once again

© 2021 Fintedex.

No Result
View All Result
  • Contact
  • Submit a News Releases

© 2021 Fintedex.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?