• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Patch fixing critical Log4J 0-day has its own vulnerability that’s under exploit

December 15, 2021
Share on FacebookShare on Twitter

Wikimedia Commons/Alex E. Proimos

Last Thursday, the world learned of an in-the-wild exploitation of a critical code-execution zero-day in Log4J, a logging utility used by just about every cloud service and enterprise network on the planet. Open-source developers quickly released an update that patched the flaw and urged all users to install it immediately.

Now, researchers are reporting that there are at least two vulnerabilities in the patch, released as Log4J 2.15.0, and that attackers are actively exploiting one or both of them against real-world targets who have already applied the update. The researchers are urging organizations to install a new patch, released as version 2.16.0, as soon as possible to fix the vulnerability, which is tracked as CVE-2021-45046.

The earlier fix, researchers said on late Tuesday, “was incomplete in certain non-default configurations” and made it possible for attackers to perform denial-of-service attacks, which typically make it easy to take vulnerable services completely offline until victims reboot their servers or take other actions.

On Wednesday, researchers at security firm Praetorian said there’s an even more serious vulnerability in 2.15.0—an information disclosure flaw that can be used to download data from affected servers.

Advertisement

“In our research, we have demonstrated that 2.15.0 can still allow for exfiltration of sensitive data in certain circumstances,” Praetorian researcher Nathan Sportsman wrote. “We have passed technical details of the issue to the Apache Foundation, but in the interim, we strongly recommend that customers upgrade to 2.16.0 as quickly as possible.”

The researchers released the following video that shows their proof-of-concept exploit in action:

Log4j 2.15.0 still allows for exfiltration of sensitive data.

Researchers for content delivery network Cloudflare, meanwhile, said on Wednesday that CVE-2021-45046 is now under active exploitation. The company urged people to update to version 2.16.0 as soon as possible.

The Cloudflare post didn’t say if attackers are using the vulnerability only to perform DoS attacks or if they are also exploiting it to steal data. Researchers from Cloudflare weren’t immediately available to clarify. Praetorian researchers also weren’t immediately available to say if they’re aware of in-the-wild attacks exploiting the data-exfiltration flaw. They also didn’t provide additional details about the vulnerability because they didn’t want to provide information that would make it easier for hackers to exploit it.

A representative of the Apache Foundation, the group that stewards Log4J, said they were looking into the reports from Praetorian and Cloudflare. This story will be updated if new information warrants.

Next Post

The 15 very specific things we loved most this year

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Spider-Man ditches Xperia for a Galaxy Z Flip in Brand New Day, and the internet can’t get over it
  • NYT Connections Sports Edition hints and answers for March 19: Tips to solve Connections #542
  • I tried Amazon Alexa+, and I’ve never been this excited about a smart home assistant before
  • NYT Pips hints, answers for March 19, 2026
  • Message from 1348 Ex Voto developer Sedleo

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously