← volver
CVE-2022-23305criticalCWE-89

SQL injection in JDBC Appender in Apache Log4j V1

62Vexday Risk Score

Haz seguimiento. Ella tiene prueba de concepto pública.

ssvc Attendcvss 9.8epss 67%
de la publicación al arma0 días
Publicada en NVD18 ene
1ª PoC14 dic
probabilidad de explotación
67%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
6 productos (9 componentes)
Red Hat OpenShift Container Platform 4 · Red Hat OpenStack Platform 13 (Queens) · A-MQ Clients 2 · Red Hat AMQ Broker 7 · Red Hat JBoss Fuse Service Works 6 · y otros 1
workaround: These are the possible mitigations for this flaw for releases version 1.x: - Comment out or remove JDBCAppender in the Log4j configuration if it is used - Remove the JDBCAppender class from the server's jar files…
Corregido
55 productos (572 componentes)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Web Server 3.1 for RHEL 7 · RHEL-8-RHEV-S-4.4 - Red Hat Virtualization Engine 4.4 · y otros 50
No afectado
16 productos (2269 componentes) — porque el código vulnerable no está presente en el producto
Red Hat JBoss Enterprise Application Platform · Red Hat JBoss EAP 7.4 for RHEL 7 Server · Red Hat JBoss EAP 7.4 for RHEL 8 · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · Red Hat Enterprise Linux 7 · y otros 11
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.