news.volyx.in

Log4Shell update: second Log4j vulnerability published (lunasec.io)

698 points by freeqaz · 1740 days ago · 278 comments on HN

Article summary

A second Log4j vulnerability has been published, and Apache has released log4j 2.16.0 to mitigate the bugs in prior versions. The new vulnerability may still affect systems that were previously patched against Log4Shell. Users are advised to check their systems and apply the latest patch to ensure they are not still vulnerable. The situation is evolving, with ongoing discussions about mitigation and communication strategies.

Main themes

  • Log4j vulnerability
  • patching and mitigation
  • security best practices
  • organizational response
  • vendor responsibility
  • home network security

What commenters say

  • Some users believe that even if they have patched against Log4Shell, they may still be vulnerable to the new CVE, depending on how they patched.
  • Others think that the constant stream of updates and mitigations is overwhelming and may lead to fatigue, causing some vulnerabilities to be ignored.
  • There is a concern that large organizations may not be taking the vulnerability seriously enough, and that vendors may be downplaying their products' vulnerabilities.
  • Some commenters suggest that hosting servers externally, rather than on a home network, can help mitigate the risk of vulnerabilities like Log4j.
  • Others argue that this approach is not foolproof and that a determined attacker can still find ways to exploit vulnerabilities.
  • The discussion also touches on the topic of security best practices, such as using firewalls, fail2ban, and Docker containers to isolate and secure servers.
  • Some users express frustration with the lack of action from vendors and managers, who may be more concerned with avoiding blame than with addressing the vulnerability.
  • There is also a concern that the vulnerability may be exploited by ransomware attackers, leading to further security breaches.