Affected versions
- Versions 1.68.03 or older;
- Versions 2.0.0 and 2.1.0.
Remote code execution with this vulnerability is not possible, however the system is susceptible to an information leak via DNS, particular regarding CVE-2021-44228 and CVE-2021-45046.
InCenter is not exploitable by CVE-2021-45105 and CVE-2021-44832.
Fix Information
The vulnerability is fixable by adding the following JVM property to the startup of the log database: -Dlog4j2.formatMsgNoLookups=true
This fix mitigates both CVE-2021-44228 and CVE-2021-45046.
See the applicable section below. For more detail, please don’t hesitate to contact Clavister Support!
Incenter 2.0 or older
Log in to the underlying operating system (via console or ssh if that is enabled) with administrator credentials. Add the property by executing the following command once:
echo -Dlog4j2.formatMsgNoLookups=true | sudo -u elasticsearch tee -a /etc/elasticsearch/jvm.options
Then reboot the whole system, or restart the log database by executing the following command:
sudo systemctl restart elasticsearch.service
The restart could potentially take some time depending on the size of the log database. Receiving logs may not be possible during that time.
Incenter 2.1 or newer
Log in to the underlying operating system (via console or ssh if that is enabled) with administrator credentials. Add the property by executing the following command once:
echo -Dlog4j2.formatMsgNoLookups=true | sudo -u opensearch tee -a /usr/share/opensearch/config/jvm.options
Then reboot the whole system, or restart the log database by executing the following command:
sudo systemctl restart opensearch.service
The restart could potentially take some time depending on the size of the log database. Receiving logs may not be possible during that time.
Security Patches
The issue will be fixed in all future versions of InCenter.
References
- https://www.clavister.com/advisories/security/clav-sa-0297-high-severity-vulnerability-in-apache-log4j2
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
- https://nvd.nist.gov/vuln/detail/CVE-2021-45046
- https://nvd.nist.gov/vuln/detail/CVE-2021-45105
- https://opensearch.org/blog/releases/2021/12/update-to-1-2-1/
- https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476
Related articles
15 Jan, 2024 dictionary troubleshoot core stream incontrol incenter oneconnect cloudservice
4 May, 2021 easyaccess incenter syslog
14 Dec, 2021 easyaccess log4j
15 Dec, 2021 core idp ipreputation log4j