Advisories ยป MGASA-2022-0002

Updated log4j packages fix security vulnerability

Publication date: 03 Jan 2022
Modification date: 03 Jan 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-44832

Description

Apache Log4j2 is vulnerable to a remote code execution (RCE) attack where
an attacker with permission to modify the logging configuration file can
construct a malicious configuration using a JDBC Appender with a data
source referencing a JNDI URI which can execute remote code. This issue is
fixed by limiting JNDI data source names to the java protocol
                

References

SRPMS

8/core