Juniper R2 2021 - Log4j vulnerability verification and correction

Description

The 'formatMsgNoLookups' property was added in version 2.10.0, per the JIRA Issue LOG4J2-2109 that proposed it. Therefore the 'formatMsgNoLookups=true' mitigation strategy is available in version 2.10.0 and higher, but is no longer necessary with version 2.16.0, because it then becomes the default behavior .

Environment

None

Potential Workaround

None

Checklist

hide

TestRail: Results

Activity

Show:

Oleksii Petrenko December 30, 2021 at 7:33 AM

Deployed to Juniper BF. Closing

Kevin Day December 17, 2021 at 10:45 PM

 

I have a PR in place that result in the following dependency structure:

The only problem seems to be the 1.2.17 coming in even though it is set to manage 2.16.0.

Removing the dependency via exclusion causes logs to not show.
This concerns me that more work is needed, possibly updating edge-common (which is a 2.x version!).

Given that it is a Friday near a holiday, I put the PR in now in its current state.
The state is an improvement, but it may still need more work.

Also note, that this for fixing CVE-2021-4104 rather than CVE-2021-44228.
Both are exploits of utilizing JNDI, its just that their vector of attack is slightly different.

 

Kevin Day December 17, 2021 at 8:30 PM

Re-opening because I found a related Log4J Vulnerability that merits the upgrade:
https://nvd.nist.gov/vuln/detail/CVE-2021-4104

Kevin Day December 16, 2021 at 4:11 PM

Version 1.2.17 of Log4J is used.
The 1.x versions of Log4J are unaffected by the security issue.

Kevin Day December 16, 2021 at 3:38 PM

I am seeing log4j version 1.2.17.
This version is not an issue to my knowledge.

Done

Details

Assignee

Reporter

Priority

Story Points

Sprint

Development Team

Prokopovych

Fix versions

Release

R2 2021 Hot Fix #5

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs
Created December 15, 2021 at 11:16 AM
Updated January 25, 2022 at 1:33 AM
Resolved December 20, 2021 at 12:50 PM
TestRail: Cases
TestRail: Runs