4 ms·
RIP jenkins installs everywhere :( : https://www.jenkins.io/blog/2021/12/10/log4j2-rce-CVE-2021-44228/ https://www.jenkins.io/blog/2021/12/10/log4j2-rce-CVE-202
by sabujp 5y ago
RIP jenkins installs everywhere :( : https://www.jenkins.io/blog/2021/12/10/log4j2-rce-CVE-2021-44228/ https://www.jenkins.io/blog/2021/12/10/log4j2-rce-CVE-2021-4...
- cure 5y agoNot really? Your link shows that the log4j is not used in core Jenkins. Moreover, they provided a nice test to see, on a particular installation, if any plugins are affected. Judging by the provided link to their issue tracker (https://issues.jenkins.io/browse/JENKINS-67361?jql=labels%20%3D%20CVE-2021-44228 https://issues.jenkins.io/browse/JENKINS-67361?jql=labels%20...), there only seem to be a handful of plugins affected, and none appear to be super widely used. They are responding really well to this, by the way. That blog post is clear and useful information is being added. Kudos to the Jenkins team!
- therealdrag0 5y agoWhat could the attack be there? Aren’t Jenkins usually private for employees use?
- mwarkentin 5y agoPrivilege escalation for a malicious employee I suppose. Also I believe there are public Jenkins instances used for OS projects, etc. aren't there?
- hn_throwaway_99 5y agoI agree with this, I think Jenkins as an attack vector is likely to be low. It's very possible, for example, to pull in a malicious dependency that then output a message that was logged and took advantage of this vulnerability. But, at that point, if you've already pulled in a malicious dependency you're probably already screwed by an easier method than this log4j issue.
- ykonstant 5y agoSeems they did a Leeroy on the Jenkins.