software library A critical vulnerability has been discovered in the Log4j , which is used by many Java programs, that could allow attackers to gain remote control over servers around the world. The vulnerability has been identified as CVE-2021-44228 .
The Log4j library collects information about errors and other events that occurred during application operation and saves it in logs. This library is used by millions of programs, games, cloud servers and corporate applications, including those from the largest manufacturers - Amazon, Apple, Cisco, Cloudflare, ElasticSearch, Red Hat, Steam.
According to TechCrunch, in order to exploit the vulnerability, attackers do not need to have deep knowledge of information security - just add one line to the web server logs, after which it will be possible to import any malicious software. Thus, until the vulnerability is closed by an update, attackers have the opportunity to hack into even well-protected cloud services of large companies.
The vulnerability received a 10 out of 10 on the Apache Software Foundation threat scale. Cybersecurity company Tenable called the vulnerability "perhaps the biggest in the history of modern computers." Cloudflare's chief security officer said he "difficult to imagine a company for which this is not a risk."
The vulnerability was discovered during Minecraft server security tests. The developers became aware of it on November 24, but the Log4j update that fixes the vulnerability did not appear until December 6. In the meantime, hackers have already begun to use the vulnerability to install remote malware on other people's computers - for example, for mining cryptocurrencies or for use in DDoS attacks. At the same time, it will take a significant amount of time to completely eliminate the vulnerability on all servers - we can talk about weeks or even months.
Cover photo: Mohammad Rahmani / Unsplash