CVE-2021-44228 Discovered
Incident window: December 10, 2021There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud. This variation claims to work around the JVM protections.
Impacted Cloud services:
VoltMX Cloud platform and services
CVE-2021-44228 details a flaw that was found in the Java logging library Apache Log4j, in versions 2.0 before 2.15.0, that are also running older JVMs. This allows an attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker’s JNDI LDAP URL and that LDAP server responds with a specially crafted payload.
This is not a critical risk on the VoltMX Platform as more recent JVMs default to not loading code over untrusted URLs. There is no attack vector for LDAP lookups on the VoltMX Platformand as always we would ask customers to be security conscious with all custom java code which they choose to upload to their environment.
The product teams, as part of due diligence, will be incorporating the latest log4j release and VoltMX Cloud will deploy the updates once available.
Impact Level : high
There is no impact to customer’s runtime environment at this time. As always, we would encourage customers to use caution when uploading custom Java code to their environments.
[2021-12-13 11:54 UTC] There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud.
[2021-12-13 11:54 UTC] The is a risk from the latest log4j attack vector and we are patching the affected products and will be updating clusters in the coming hours.
[2021-12-14 08:14 UTC] Resolved. All VoltMX environments are fully patched for CVE-2021-44228.