{"id":"GHSA-mf4f-j588-5xm8","summary":"Apache Log4j Remote Code Execution","details":"### Impact\n\nOpencast uses an Apache Log4j2 version which, combined with older JDK versions, can be used for remote code execution attacks which have been found to be actively exploited.\n\nApache Log4j2 \u003c=2.14.1 JNDI features is not sufficiently protected. An attacker who can control log messages or log message parameters can execute arbitrary code when message lookup substitution is enabled.\n\n### Who is affected\n\n- Opencast before 9.10 or 10.6 are affected\n    - Log4j version: all 2.x versions before 2.15.0 are affected\n\n### Patches\n\nThe issue has been fixed in Opencast 9.10 and 10.6.\n\n### Workarounds\n\nThe vulnerability can be mitigated by setting system property `log4j2.formatMsgNoLookups` to `true`.\n\n### References\n\n- [Opencast pull request mitigating the vulnerability](https://github.com/opencast/opencast/pull/3253)\n- [CVE-2021-44228 Detail](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)\n- [Analysis and Remediation Guidance to the Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability](https://www.veracode.com/blog/security-news/urgent-analysis-and-remediation-guidance-log4j-zero-day-rce-cve-2021-44228)\n- [VE-2021-44228 – Log4j 2 Vulnerability Analysis](https://www.randori.com/blog/cve-2021-44228/)\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [our issue tracker](https://github.com/opencast/opencast/issues)\n* Email us at [security@opencast.org](mailto:security@opencast.org)\n\n\n### Note about dependencies\n\nThis issue affects many Java applications. Please also verify these are not vulnerable.","modified":"2024-12-02T05:39:09.965185Z","published":"2021-12-14T21:07:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-12-14T15:22:20Z","nvd_published_at":null,"cwe_ids":[],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/opencast/opencast/security/advisories/GHSA-mf4f-j588-5xm8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44228"},{"type":"WEB","url":"https://github.com/opencast/opencast/pull/3253"},{"type":"WEB","url":"https://docs.opencast.org/r/10.x/admin/#changelog/#opencast-106"},{"type":"WEB","url":"https://docs.opencast.org/r/9.x/admin/#changelog/#opencast-910"},{"type":"PACKAGE","url":"https://github.com/opencast/opencast"}],"affected":[{"package":{"name":"org.opencastproject:opencast-common","ecosystem":"Maven","purl":"pkg:maven/org.opencastproject/opencast-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.10"}]}],"versions":["6.6","7.2","7.3","7.4","7.5","7.6","7.7","7.8","7.9","8.0","8.1","8.10","8.11","8.3","8.4","8.5","8.6","8.7","8.8","8.9","9.0","9.1","9.2","9.3","9.4","9.5","9.6","9.7","9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-mf4f-j588-5xm8/GHSA-mf4f-j588-5xm8.json"}},{"package":{"name":"org.opencastproject:opencast-common","ecosystem":"Maven","purl":"pkg:maven/org.opencastproject/opencast-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0"},{"fixed":"10.6"}]}],"versions":["10.0","10.1","10.2","10.3","10.4","10.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-mf4f-j588-5xm8/GHSA-mf4f-j588-5xm8.json"}}],"schema_version":"1.9.0"}