# The Log4j vulnerability : what response have you seen?

**URL:** <https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040>\
**Category:** In My Humble Opinion\
**Created:** [December 14, 2021, 11:11am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040 "2021-12-14T11:11:43Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Heracles](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/heracles/32/487_2.png) [@Heracles](https://boards.straightdope.com/u/Heracles)\
**Post date:** [December 14, 2021, 11:11am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/1 "2021-12-14T11:11:43Z")

</div>

The [CVE-2021-44228 vulnerability](https://www.cve.org/CVERecord?id=CVE-2021-44228) is serious because it’s being exploited already, allows arbitrary code execution, and the library in question may be present in any system that is (directly or indirectly) based on Java.

Here I’ve seen the governments of Canada and Québec take down all their websites; their respective home pages were back online soon after, with a message about most of their _other_ online systems getting turned them back on progressively when they’re verified as secure. Of course, a government can afford to do this.

But I haven’t seen many businesses do the same. I suspect two of the financial institutions I do business with of using Java extensively in their Web-facing systems, yet they haven’t taken down their sites and haven’t even published anything saying “We’ve checked and we’re not affected”. Of course, a bank that took down its own website for more than a few hours would be at serious risk of losing customers. Their IT staff are probably checking their systems frantically nonetheless.

What have you seen as a response so far, in your areas ? Sites taken down, reassuring messages, etc. ?

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 14, 2021, 11:33am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/2 "2021-12-14T11:33:34Z")

</div>

> [@Heracles](#):
>
> What have you seen as a response so far, in your areas ? Sites taken down, reassuring messages, etc. ?

Surprisingly little. I’ve had calls from a few clients to confirm that  
A) we weren’t vulnerable and b) nothing we have done for them is affected.

We’re a 100% Microsoft shop, so no Java for us. I did have to update our network controller software, but the vendor had an updated version out on Friday.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 14, 2021, 11:35am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/3 "2021-12-14T11:35:16Z")

</div>

Nvidia put out a notice on their security page (which I check to see if I need to update my drivers.) They simply say they’re investigating if they need to make any changes and will update as they do.

> [NVIDIA Product Security | NVIDIA](https://www.nvidia.com/en-us/product-security/)

---

<div class="post-metadata">

**Author:** ![wolfpup](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpup/32/10618_2.png) [@wolfpup](https://boards.straightdope.com/u/wolfpup)\
**Post date:** [December 14, 2021, 11:39am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/4 "2021-12-14T11:39:24Z")

</div>

CNN has a story on it. Apparently security experts are regarding it as a pretty big deal:

> **[US warns hundreds of millions of devices at risk from newly revealed software...](https://www.cnn.com/2021/12/13/politics/us-warning-software-vulnerability/index.html)**
>
> Hundreds of millions of devices around the world could be exposed to a newly revealed software vulnerability, as a senior Biden administration cyber official warned executives from major US industries Monday that they need to take action to address...

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 14, 2021, 11:40am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/5 "2021-12-14T11:40:34Z")

</div>

Valve has confirmed that Steam isn’t vulnerable, according to this reddit post:

> **[r/Steam - A vulnerability in Log4j(Java logging package) affect Steam.](https://www.reddit.com/r/Steam/comments/rd68yp/comment/ho1yyaa/)**
>
> 76 votes and 30 comments so far on Reddit

---

<div class="post-metadata">

**Author:** ![icon](https://avatars.discourse-cdn.com/v4/letter/i/c6cbf5/32.png) [@icon](https://boards.straightdope.com/u/icon)\
**Post date:** [December 14, 2021, 11:45am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/6 "2021-12-14T11:45:50Z")

</div>

At my office, we started working on mitigating the problem this Saturday and although the systems that I work with were taken care of then (with a few minutes of down time) additional work continued until yesterday. I also should clarify that it is not all Java based systems, just the ones that use that particular library. It is widely used by webservers and the like, but just having Java on your system does not automatically mean you have Log4j.

Minecraft, servers and Java clients, do make use of it, so Minecraft users were notified over the weekend to upgrade both. They don’t control the servers that people have spun up on their own so they can’t do much on their end, other than provide a way to update for those.

`//i\\`

---

<div class="post-metadata">

**Author:** ![wolfpup](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpup/32/10618_2.png) [@wolfpup](https://boards.straightdope.com/u/wolfpup)\
**Post date:** [December 14, 2021, 11:56am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/7 "2021-12-14T11:56:02Z")

</div>

Information from Symantec here:

> **[Apache Log4j Zero-Day Being Exploited in the Wild](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/apache-log4j-zero-day)**
>
> Symantec products will protect against attempted exploits of critical CVE-2021-44228 vulnerability

---

<div class="post-metadata">

**Author:** ![Broomstick](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/broomstick/32/246_2.png) [@Broomstick](https://boards.straightdope.com/u/Broomstick)\
**Post date:** [December 14, 2021, 12:01pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/8 "2021-12-14T12:01:40Z")

</div>

Could someone please translate that into non-tech for us end users? I gather this is some sort of vulnerability, but I have no idea how this is relevant to me (other than !Danger, Will Robinson! alert that there is a security issue). What does the average (non-corporation) person need to know or do here?

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 14, 2021, 1:00pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/9 "2021-12-14T13:00:20Z")

</div>

> [@Broomstick](#):
>
> Could someone please translate that into non-tech for us end users? I gather this is some sort of vulnerability, but I have no idea how this is relevant to me (other than !Danger, Will Robinson! alert that there is a security issue). What does the average (non-corporation) person need to know or do here?
> 
> Thank

There is a bug in a Java library that writes out logs. If the system is affected, you can put the exploit in a field in a web page that saves the entry for debugging and informational purposes. The component that handles the logging, log4j, unintentionally runs the code while trying to save the log bypassing any security that would normally be in place.

This only affects systems that a) don’t cleanse the input b) are running Java c) are using the affected versions of log4j. For example, my firewall runs Java but they are not using a vulnerable version of log4j.

If your home internet router has this issue and is accessible from the internet, it could be a big issue. If it is accessible only from your home, it’s a much smaller risk.

---

<div class="post-metadata">

**Author:** ![kitap](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@kitap](https://boards.straightdope.com/u/kitap)\
**Post date:** [December 14, 2021, 1:08pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/10 "2021-12-14T13:08:28Z")

</div>

Our tech support is located in New Jersey or something. I’m sure they’re looking into it but unless they need protracted downtime to fix it we’ll never know what they might or might not need to do.

---

<div class="post-metadata">

**Author:** ![Heracles](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/heracles/32/487_2.png) [@Heracles](https://boards.straightdope.com/u/Heracles)\
**Post date:** [December 14, 2021, 1:09pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/11 "2021-12-14T13:09:09Z")

</div>

Well, basically, it’s a security hole that may affect server-based software and especially websites, if they are built using a certain set of tools and use some versions of a library called Log4j. Log4j is used for logging (writing technical logs about event sequences), and it costs nothing to use, so it’s included for troubleshooting purposes in many pieces of software. An attacker could execute code of their choosing, remotely, simply by putting in some specific text on a website form. Depending on the privilege level of the affected software, it may allow an attacker to install additional software, steal information, damage a website or a company’s corporate systems.

There isn’t much you can do as an ordinary citizen. It’s unlikely that the vulnerability would affect your phone or tablet, or even your PC or Mac.  
ETA: Good point about the router, @FinsToTheLeft , I hadn’t thought about that. Yes, there is some danger in your home after all.

It’s more something your employer, your government, the companies you deal with, need to fix. You may be affected in various ways, as a direct or indirect user.

---

<div class="post-metadata">

**Author:** ![kferr](https://avatars.discourse-cdn.com/v4/letter/k/71e660/32.png) [@kferr](https://boards.straightdope.com/u/kferr)\
**Post date:** [December 14, 2021, 1:22pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/12 "2021-12-14T13:22:13Z")

</div>

One non-technical analogy I’ve heard is that it’s like if someone sends you a postcard with a special message on it then all the doors in your house unlock.

---

<div class="post-metadata">

**Author:** ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)\
**Post date:** [December 14, 2021, 1:46pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/13 "2021-12-14T13:46:51Z")

</div>

The reaction for my team has been a scramble to pull a release that was set to go out the door so we could patch it, and plan for two patches on earlier release streams to deliver the fix there. Some long calls with all our affected developers to craft a new schedule, analyze the impact on our systems, and write an advisory for customers detailing how they can adjust their configuration to alleviate the threat.

Busy times, job security.

---

<div class="post-metadata">

**Author:** ![Broomstick](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/broomstick/32/246_2.png) [@Broomstick](https://boards.straightdope.com/u/Broomstick)\
**Post date:** [December 14, 2021, 1:57pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/14 "2021-12-14T13:57:42Z")

</div>

> [@FinsToTheLeft](#):
>
> If your home internet router has this issue and is accessible from the internet, it could be a big issue. If it is accessible only from your home, it’s a much smaller risk.

I don’t think my home router is internet accessible, but how do I find out for sure? How would I find out if my firewall uses the bad log4j?

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 14, 2021, 2:26pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/15 "2021-12-14T14:26:01Z")

</div>

> [@Broomstick](#):
>
> I don’t think my home router is internet accessible, but how do I find out for sure? How would I find out if my firewall uses the bad log4j?

Just Google [Router Manufacturer] [Model] Log4J, and see if your router manufacturer has published updated firmware. If so, you should see instructions to download and update the firmware.

---

<div class="post-metadata">

**Author:** ![Heracles](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/heracles/32/487_2.png) [@Heracles](https://boards.straightdope.com/u/Heracles)\
**Post date:** [December 14, 2021, 2:38pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/16 "2021-12-14T14:38:09Z")

</div>

Yep, good analogy.

Our minister of Government Digital Transformation (the computer guy at the government) said that inspecting government systems for this vulnerability is like doing an inventory of all 60-watt light bulbs in all government buildings.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 14, 2021, 3:32pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/17 "2021-12-14T15:32:23Z")

</div>

Java is popular on routers and modems? That just seems so odd to me. The ones I’ve seen always seemed like they were running some version of Linux with a custom shell, with a very basic webserver. Running Java on top of that would seem inefficient.

Then again, the web interface to the modem of my new ISP does seem to be a lot slower than my old one, despite the device itself being a lot larger. It actually shows a loading page in between every page load, which seems odd for what should be a simple http server.

But I also can’t find anything related to Log4j about it. Just some security holes on old firmware versions.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 14, 2021, 4:03pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/18 "2021-12-14T16:03:37Z")

</div>

> [@BigT](#):
>
> The ones I’ve seen always seemed like they were running some version of Linux with a custom shell, with a very basic webserver

Many basic (even appliance) web servers are written in Java. If you’re building your network appliance using open source components, Java may wind up in the mix.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 14, 2021, 4:43pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/19 "2021-12-14T16:43:07Z")

</div>

Huh. Are they running Java natively, like old cell phones did? I’d think that native code would be needed for performance on such low end hardware (relative to PCs and phones).

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 14, 2021, 4:50pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/20 "2021-12-14T16:50:08Z")

</div>

> [@BigT](#):
>
> Are they running Java natively, like old cell phones did?

Nope. Java runtime VMs are available for many of the SOC-type hardware that net appliances are now based on. Hardware performance has advanced quite a lot and Java runtimes are a little more efficient than they used to be.

And the JVM isn’t running the core firewall/router functions. That’s still native code in kernel or high-privilege userland.

[Next page](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040.md?page=2)
