3 ms·
This is very similar to the log4j vuln or not? I had expected that all code like that would have been scrutinized immediately.
by Bootvis 4y ago
This is very similar to the log4j vuln or not?
I had expected that all code like that would have been scrutinized immediately.
- topspin 4y ago> This is very similar to the log4j vuln or not? Yes, it appears similar. It involves string interpolation that leads to arbitrary code execution via crafted values. It's also similar in that Apache Commons components are widespread and deeply embedded in innumerable backend systems. I wonder how widespread this particular Commons component is in real world. I can't recall ever explicitly seeking it out as a direct dependency myself. However, it is probably a common transitory dependency. It shows up as being used by a few thousand other Java components on mvnrepository.com, although at first glance I didn't see things in the list of usages that made me panic. The ones that stick out are Commons JPA, Apache ServiceMix and Apache Turbine and Struts 2. Disclaimer: The above is not comprehensive. Just me clicking around a few minutes. Don't bet your career on it.
- groestl 4y agoSimilar, yes, but (I might be wrong here) the severity in log4j stems from the fact that interpolation was happening on a logged string, and most users did expect this to be passed through unmodified (i.e. param1 in log.info(param1)). Here, the interpolation happens on a string that is expected to be a template (it's even documented that way), so users would usually be cautious where the template originates from. Recursive interpolation also needs to be enabled explicitly.