Dear customer,
You probably have heard about the vulnerability issue that researches have found in an Apache log4j library. Apache Log4j is an open source framework that is used to keep track of activity within an application. An application using log4j is vulnerable at the moment a malicious HTTP call from the outside world lands unchanged and is logged in this application using an older version of log4j. The vulnerability has been reported with CVE-2021-44228.
Log4j 2 vulnerability (CVE-2021-44228)
The NCSC is advising organizations to take steps to mitigate the Apache Log4j 2 vulnerability.
More details can be found here: Alert: Active scanning for Apache Log4j 2 vulnerability... - NCSC.GOV.UK
Human Inference is actively responding to this vulnerability.
Log4j is used on several locations:
Log4j in DataPlatform
In DataPlatform we are using log4j as an internal logging mechanism. No HTTP traffic can reach the mechanism from outside through the protocol that is used within DataPlatform. Even though there is no vulnerability here we decided to update the libraries in an upcoming release anyway.
Log4j in Apache Tomcat
Apache Tomcat does not use log4j, while applications deployed in Apache Tomcat might use log4j within. Most customers will not expose their Tomcat server to the outside world, but in case this is done, log4j might be abused. The vulnerability abuses the so called “Message Lookups”.
Despite DataPlatform does not use this functionality anywhere we strongly advise to switch off the possibility anyway.
Several ways to mitigate the vulnerability are described on internet. We advise to do this by passing the following parameters at the startup of Apache Tomcat to true:
This is how these parameters can be passed:
Where and how to pass this parameter highly depends on your specific Tomcat installation.
Log4j in DataHub
The core of DataHub makes no use of the Log4j library and therefore is not vulnerable for the remote code execution.
For the instance of Apache Tomcat that runs both DataHub and CAS, we advise to use the same settings as described above. This, because DataHub makes use of Apereo CAS for Authentication. Apereo CAS makes use of Log4j.
Log4j in Elasticsearch
DataHub makes use of Elasticsearch and Elasticsearch itself is using log4j within. To prevent the usage of “Message Lookups” we do advise to use the same settings as advised for Apache Tomcat:
For more information we refer to this site:
Log4j2 vulnerabily updates (January 5, 2022)
Since our first report on December the 14th new security vulnerabilities in log4j2 have been reported and new versions of log4j have been released. (Log4j 2.16.0, 2.17.0, 2.17.1…)
Latest updates on log4j2 can be found on the apache.org website: Log4j – Apache Log4j 2
Although in most situations having a log4j within our product is no vulnerability risk at all, we decided to keep our software up to date with new releases of log4j.
For both DataHub and DataPlatform new releases with the latest updates are available.
For all environments we still advise to disable message lookups in both Apache Tomcat and in Elasticsearch (as described above)
For more information about latest software releases or vulnerability risks on your specific DataHub or DataPlatform environment, please contact support@humaninference.com.
Worstel je met het beheren van de enorme hoeveelheid gegevens die jouw organisatie verzamelt? Met de alsmaar strenger wordende regelgeving is het goed beheren van je data belangrijker dan ooit. Gelukkig is er een softwareoplossing die hierbij ondersteunt: Master Data Management (MDM).
Neem contact met ons op voor een kort kennismakingsgesprek over hoe MDM jouw organisatie helpt om succesvol te zijn. Zonder verdere verplichtingen, maar met waardevol advies.
Slechte datakwaliteit kost organisaties honderdduizenden euro’s per jaar: onbetrouwbare data leiden tot foute beslissingen en inefficiënte processen.
Gelukkig is er onze datakwaliteitschecklist, waarmee je in 5 minuten beoordeelt of jouw data voldoen aan de 6 datakwaliteitsdimensies. Laat je gegevens achter en download direct het document.
Een effectief compliance-proces is essentieel voor het beschermen van je organisatie tegen risico’s. Onze experts staan klaar om je te helpen met advies en de juiste tools voor een toekomstbestendig compliance beleid, zoals CDD.
Laat je gegevens achter en neem contact met ons op voor een kort kennismakingsgesprek. Zonder verdere verplichtingen, maar met waardevol advies.