25 ms·
Log4j 2.16: Certain strings can cause infinite recursion
- ggfgg 5y agoOh this is just a gift that keeps giving.
- nafey 5y agoFeels like a bad comedy movie.
- input_sh 5y agoAt this point I feel like just shutting down anything Java-based until Log4j reaches version 2.20 or something.
- lstodd 5y ago2.20 would stand for 2^20 vulnerabilities. I decided to just ditch it and write from scratch something api-compatible, but extremely cut-down on "features". Maybe someone would release something along this line. I can't.
- solarengineer 5y agoYou could consider alternatives such as logback instead of writing your own.
- lstodd 5y agoA case of scare of old codebases. Decision was made to have at least some control.
- kazen44 5y agothis is basically what the openbsd community as done with several protocols/systems. LibreSSL is a complete rewrite of the openssl functionality with drastically fewer features. Same goes for CARP. Maybe running software with minimal defaults is a good thing, as it forces the users of the system/library/whatever to think about its behaviour and usecase.
- foxfluff 5y agoLibreSSL is a fork, not a complete rewrite.
- albertopv 5y agoUse logback, spring boot default.
- aluket 5y agoLogback isn’t entirely immune: https://cve.report/CVE-2021-42550 https://cve.report/CVE-2021-42550, although access to the configuration file is required.
- nafey 5y agoI wonder how difficult will it be to increment the major version and turn off all features that can lead to these vulnerabilities.
- silon42 5y agoTime to fork and start removing features.
- gjvc 5y agohttps://tinylog.org/v2/ https://tinylog.org/v2/
- deleted 5y ago[deleted]
- throwaway4good 5y agoI like java.util.logging.
- mrweasel 5y agoUnless you're doing something very special, is there any reason to not use Javas build in logger? I don't know any Python developers that doesn't just use the logger in the standard library. I'm not a Java developer, so I don't know, but is there something "wrong" with java.util.logging?
- hocuspocus 5y agoJUL is weird and came too late to stand a chance against commons logging and log4j. Log4j's API façade was successfully abstracted away into Slf4j, whose usage became ubiquitous in the Java ecosystem. You certainly can use JUL as an Slf4j backend though.
- vbezhenar 5y agoThere's nothing wrong with java.util.logging. logback/log4j are better in almost every regard (configuration, usability, speed), but if you don't mind to write some boilerplate, jul is absolutely appropriate for most projects.
- narengowda 5y agoNot again
- Freak_NL 5y agoThis looks worrying, but if you read the issue thread it seems that this can only be triggered if you can edit the pattern string of the logger. This is something you can only do on the server itself (if made configurable) or in the build artefact that you deploy. From a quick glance at the comments this looks like a minor issue due to the attack vector being very, very small — i.e., the attacker must have access to where the logging pattern is defined, and if that is the case, this attack is probably not the most worrisome they could pull off. I hope I'm not wrong, otherwise we'll be patching everything again.
- koolba 5y ago> This looks worrying, but if you read the issue thread it seems that this can only be triggered if you can edit the pattern string of the logger. This is something you can only do on the server itself (if made configurable) or in the build artefact that you deploy. Plenty of existing code does things like: log.info(“foo: “ + request.getFoo()); Rather than using fixed format strings and {} place holders. You’re not supposed to, but it’s far from uncommon.
- karatinversion 5y agoOh yes, I’ve seen several programs that spend ~30% of their CPU cycles formatting strings that are immediately thrown away because the log level is not high enough. Now you can also include vulnerabilities with no extra effort!
- dmurray 5y agoIn Java? Surely one of the benefits of the JIT is to compile logger.debug() into a no-op if the log level is not high enough.
- clon 5y agoYou would still be doing the job of concatenating together the error message, possibly rendering some complex objects to a string, that is then fed to the no-op. The point parent was making is that there is also a performance aspect to this, in addition to the security aspect.
- hoffs 5y agoThe comments show that nobody can prove a reliable attack vector of DOS in 2.16
- heisenbit 5y agoThe risk for a denial of service by a malicious programmer are much lower than the DOS risk posed by a distracted programmer. Looking at the typical attack surface in an enterprise app a distracted programer can stumble on to trigger a DOS the risk of stumbling on the log4j recursion by accident is minuscule.
- garydgregory 5y agoWe just released Log4j 2.17.0 which addresses this issue: https://logging.apache.org/log4j/2.x/download.html https://logging.apache.org/log4j/2.x/download.html
- sebazzz 5y agoGood job! I really don't envy you right now, being in the center of attention like you are now. Take care!
- dSebastien 5y agoAwesome work. I read a lot of negative things about log4j these days, but people forget how great log4j was compared to whatever the JDK provided us with. It served a useful purpose for most developers, and inspired many libraries in other languages. Take care!
- deleted 5y ago[deleted]
- sto_hristo 5y agoLets make a program that can print strings and do log rotation. Then overly complicate it, put everything in it. wcgw?
- classified 5y agoBut I want my logger to brew me a coffee via the network card in my coffee machine. A logger that's not Turing-complete is definitely under-featured.
- nottorp 5y agoThat's what we're missing. Anyone knows log4j enough to write a proof that it's Turing complete? How about it passing the Turing test?
- stjohnswarts 5y agoI want my logger accessible/controlled from my nintendo switch so I can check logs while I game.
- christophilus 5y agoYou just need fast print strings. Leave log rotation up to the OS and it’s tools.
- vbezhenar 5y agoHow does it work? Do I need to close/reopen file after every log message?
- darthShadow 5y agoNo, just close and re-open the file when you receive a specific signal, generally SIGHUP, from logrotate or any equivalent tool.
- vbezhenar 5y ago
- perfunctory 5y agoReading stories like this makes me very sad about the state of my profession. Something that is supposed to be a simple stupid logging library is on the front pages of the mainstream media due to all the havoc it's causing. We really have a long way to grow up as a profession.
- sirwhinesalot 5y agoHardware is a mess, operating systems are a mess, programming languages are full of poor design decisions, foundational libraries are a mess and maintained by unpaid volunteers. Our field is royally screwed, whole thing needs to be rethought.
- allendoerfer 5y agoAnd yet here we are taking over the world.
- sirwhinesalot 5y agoIndeed, how scary is that? ;)
- goblin89 5y agoSoftware architecture is a non-pure field where other fields, sciences and art routinely intersect to meet human factor and impact real world (ideally, improve it and solve problems). Any such field is in varying degrees of messiness (medicine, agriculture, architecture, you name it). Mistakes are made constantly, have real consequences (people die), and hopefully are discovered and admitted sooner rather than later. All we can is (cliché warning) do our best, keep growing, act responsibly and be humble.
- fulafel 5y agoI agree but the supposing part seems a bigger problem... log4j is not small or simple or understandable and this is easy to discover if you glance at it, I think the problem is more in underappreciating simplicity (aka overtolerating complexity).
- pdevr 5y agoAvoid frameworks and libraries whenever possible. The last time I benchmarked java.util.logging though, it lost out to log4j by a wide enough margin. Has anyone done any benchmarking lately?
- HatchedLake721 5y agoYes, let’s reinvent the wheel, waste time and resources every time! Who needs decades of battle tested, proven methods and tools? Who needs thousands of human hours behind thousands of GitHub issues and pull requests? Let’s do everything from scratch! Hm, why is there JavaScript fatigue and 10 new frameworks every month?
- kreeben 5y agoDidn't log4j show us that "battle tested, proven" means nothing?
- coldcode 5y agoNothing in programming is proven since everything changes all the time. Otherwise we would still be programming in Cobol, Fortran, LISP and APL without changes from the 1950's. It's like saying tanks from WW1 were good enough to last forever. Change means you have to prove things over and over, and generally the pace of change is too fast for anything to be proven before it is obsolete.
- csmpltn 5y ago> "Didn't log4j show us that "battle tested, proven" means nothing?" Exactly the kind of comment you'd get from an inexperienced junior developer. There are bugs in every software stack, and bugs can be fixed. We fix the bugs, and we move on in life.
- bluesnowmonkey 5y agoThat’s an ad hominem attack. It shuts down conversation rather than encouraging it. Not the level of discourse we should be seeing on here. Everybody is allowed to have an opinion regardless of their background. Anyway I have >20 years of experience and say kreeben has a point. The popularity of this library is working against it, preventing it from reversing bad decisions, and multiplying the harm. Sometimes it’s worthwhile in the long run to throw away the “battle tested” thing in favor of a newer, simpler alternative.
- mnd999 5y agoThree releases for essentially the same bug in a week is not okay. Just shut this project down. It’s seemingly a cesspit of bad code, bad testing and general incompetence.
- bpicolo 5y agoEvery project has bugs. Log4j just also happens to have literally the most scrutiny on the planet right now. That's actually a great thing for the long term health of the project - it's getting a whole lot of free auditing right now. Many millions of dollars worth.
- soneil 5y agoWe have systems still using 1.2.x. Do you think if they closed the doors today, the problem would magically disappear? We'd have it ripped out of circulation, replaced by christmas, and everything would be magically easy? There's an old joke, goes something like: “Recently, I was asked if I was going to fire an employee who made a mistake that cost the company $600,000. No, I replied, I just spent $600,000 training him. Why would I want somebody to hire his experience?”. That's what's happening for log4j right now. A lot of eyes, a lot of attention, stuff's going to come out - and long-term it'll be better off for it. Shutting it down and moving to something else that hasn't been tested in battle isn't the pay-off it sounds like.
- tetha 5y agoThat's fairly normal. I'd rather patch everything 5 times in a row to get rid of one RCE at a time, rather than running with a 10/10 vulnerability for 5 days so the application can make sure to root out all possible problems.
- keyle 5y agoThis is nothing surprising. I'm not talking about the bug, but the report. If you shine a thousand spotlights at a problem, you'll find more problems. Glad this library is finally getting the code review it deserves. Hope the whole SDK gets the fine-tooth comb treatment it is overdue. Like it or not... 50% of the Internet runs on Java (and my statistics are 50% accurate. I swear, 50% of the time.)
- blablabla123 5y agoDefinitely there's no reason why Java libraries couldn't be as polished as in other popular languages. (Or why every Enterprise pattern should be present.) It's easy to just consume libraries and complain when they fail instead of contributing. Although I realize that a large part of the user base is corporate and just getting a permission to contribute during work hours can be problematic.
- imglorp 5y agoIt's not just getting permission--and maybe I'm generalizing way too far here--but it seems much of "enterprise" java culture is oriented around commoditized, interchangeable cog people who meet KPIs just like it's composed of commoditized, interchangeable components which implement interfaces. So they get cog behaviors, as designed. Polished, masterful, crafted product is hard to KPI for.
- rp1 5y agoI think you’re generalizing way too much. Java is old. The libraries are old. There is a lot of bad old code out there, and very little glory in fixing it.
- sofixa 5y ago> Like it or not... 50% of the Internet runs on Java Highly unlikely. Most of the internet runs on PHP, WordPress more often than not (there are stats on that, but I'm on mobile and can't check right now).
- blastonico 5y agoGet away from languages like C, they said. There are double free, dangling pointer, undefined behavior, they said. Wow, a LOGGER engine that execute arbitrary code. wow
- oconnor663 5y agoI think the natural point of comparison with C here would be printf().
- SAI_Peregrinus 5y agoPrintf at least doesn't recursively expand the format string.
- lanstin 5y agoAnd one of the good things in Go is that you can pass arbotrary crap to fmt.Printf and it wont crash or overflow anything. So logging errors don't kill you (unlike c or python). Ironically, tho, my tool to scan all our jar files for log4j has revealed a panic in archive/zip, something to do with a zero length file name.
- johnisgood 5y agoRust rewrite when?
- deleted 5y ago[deleted]
- alcover 5y agoThe weakness is in the logger itself here, not Java per se.
- stjohnswarts 5y agoI think it's more about the odds than that "there will never be an arbitrary execution bug in python/javascript/java/rust"
- imglorp 5y agoThere's a new CVE filed for it, just now. And here are the others for reference. 12/18 - https://nvd.nist.gov/vuln/detail/CVE-2021-45105 https://nvd.nist.gov/vuln/detail/CVE-2021-45105 Score: - 12/14 - https://nvd.nist.gov/vuln/detail/CVE-2021-45046 https://nvd.nist.gov/vuln/detail/CVE-2021-45046 Score: 3.7 12/14 - https://nvd.nist.gov/vuln/detail/CVE-2021-4104 https://nvd.nist.gov/vuln/detail/CVE-2021-4104 Score: 8.1 12/10 - https://nvd.nist.gov/vuln/detail/CVE-2021-44228 https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Score: 10.0
- smarx007 5y agoCVE page for 45046 says that the score is being revised. Log4j self-assesses 9.0/10 as the new score: https://logging.apache.org/log4j/2.x/security.html https://logging.apache.org/log4j/2.x/security.html (see under Fixed in Log4j 2.12.2 (Java 7) and Log4j 2.16.0 (Java 8)). And the new CVE-2021-45105 is self-assessed to have a CVSS of 7.5/10 (see the same page above).
- spydum 5y agoWhat surprises me is the scoring... for a non-default config. Seems a little high, but these seem inflated, maybe just because of the attention.
- smarx007 5y agoI think the scoring is done from the assumption that many users may be concatenating a log string instead of formatting it. If you format your log strings, 7.5 is definitely too high.
- majou 5y agoThe scoring has little merit in general.
- terom 5y agoParticularly with the `${ctx:...}` vs `%X{...}` distinction. For a plain DoS, which only affects `${ctx:...}` usage? I wouldn't panic, fix it if someone manages to actually exploit it... It's goods new so far that with more people/time and attention paid to the log4j exloits, the vulnerabilities are just getting narrower in scope and lesser in impact.
- tomohawk 5y agoThe author of log4j abandoned it and wrote logback. That plus slf4j seem like a better path than sticking with log4j.
- throwbynight38 5y agoI'm not sure there was really a need for log4j2, and I think the name itself is what drove most people to it.
- jokoon 5y agoSometimes I wonder if it would be possible to estimate the probability of the presence of nasty vulnerabilities like this one on a software stack. At one point, it seems that "everyone use this so it must be secure enough" replaced "we're a large company, did we spend enough time reviewing code of the open source stuff we use?". It seems the Linus's quote "given enough eyeballs, all bugs are shallow", is not really true. Imagine if a well funded agency like the NSA employed at least hundreds of full time developers whose job would be to sniff for those vulns. I'm pretty sure you could automate searching for those vulns, and that only the NSA has such tool.
- xvector 5y agoThen again, if Log4j wasn't open source, the NSA could still run said tool while most of these bugs would go completely unfound.
- mschuster91 5y agoThe current bug was either found or first exploited by Minecraft trolls, to bring down servers and clients via chat. If you want to find issues in a code library, embed it somewhere in the hot code paths of a game or DRM system to maximize the number of eyeballs looking at every single instruction.
- stjohnswarts 5y agoHonestly there's an excellent chance they already discovered it and are using it right now, or at least up til the past week or so.
- atonse 5y agoThat’s what Google’s project zero is. The problem is, there are a vanishingly small amount of engineers talented enough to find these kinds of things. And if NSA wanted to hire a few hundred they’d have to go the defense contractor route which will inevitably lead to them getting 1 great engineer and 499 extremely mediocre ones.
- 5y ago
- wly_cdgr 5y agoDo they just, like, not have a QA department over there? Have people really still not understood that they amount of resources spent on QA must be exponentially proportional to dependents count? And that QA, not software "engineering", is the most important job that requires the most highly qualified people?
- skeeks 5y ago"they"? It's an open source software. What exactly do you expect?
- wly_cdgr 5y agoI expect open source developers not to release projects or updates that they reasonably expect many others will choose to depend on unless they are willing and able to do extensive, thorough, sophisticated QA on them. Contributing to open source is a privilege, not a right
- throwbynight38 5y agohttp://www.slf4j.org/ http://www.slf4j.org/
- IsThisYou 5y agoI still try to understand why anybody would want a logger that executes embedded code and loads remote code from aribtrary web urls. That's like having a toaster that needs regular tire changes so it doesn't run me over.
- hn_throwaway_99 5y agoPerhaps I missed this, and I get there are backwards compatibility issues, but can't a version ship where default is that the logged strings (not formatting strings) are not parsed at all. This seems like a major design flaw - I don't want my logging library doing any parsing of the logged input.
- martini333 5y agoThe gift that keeps giving!
- revskill 5y agoOne reason to adopt microservice architecture. Stop import logging library, and build a logging service instead.
- inkeddeveloper 5y agoI’m going to stop you right there.
- xg15 5y agoSo, let me get this: Log4j is disabling JNDI, fixing various string substitution issues and who knows what else, but the root cause of the whole mess - that Log4j attempts string substitution on the actual parameter values remains untouched? Why?
- stjohnswarts 5y agoI wonder if this won't be a boon for them in the long run. Lots of eyes on log4j security nowadays, it will come out stronger if with fewer users. I imagine a lot of user have switched to other logging solutions now or plan to in the near future.