Apache Log4j·´ÐòÁл¯´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17571£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Log4j 1.2.27¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


Apache Log4jÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚJavaµÄ¿ªÔ´ÈÕÖ¾¼Í¼¹¤¾ß¡£¡£¡£


Apache Log4jÖаüÀ¨Ò»¸ö SocketServer À࣬£¬£¬£¬£¬£¬£¬ËüÈÝÒ×Êܵ½²»¿ÉÐÅÊý¾Ý·´ÐòÁл¯µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ±Ê¹Ó÷´ÐòÁл¯Ð¡¹¤¾ß¼àÌý²»¿ÉÐÅÍøÂçͨѶÁ÷ÒÔ»ñÈ¡ÈÕÖ¾Êý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


Apache¹Ù·½ÒÑÔÚа汾ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬Apache Log4j 1.2 °æ±¾¹Ù·½ÒÑÓÚ2015Äê8ÔÂ×èֹά»¤£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶µ½ 2.8.2 »ò¸ü¸ß°æ±¾£ºhttp://logging.apache.org/log4j/2.x/index.html¡£¡£¡£


²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2019/12/19/2