-
Notifications
You must be signed in to change notification settings - Fork 258
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
30 changed files
with
90 additions
and
107 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,108 +1,36 @@ | ||
## Intro | ||
Log4j impact manufacturers and components summary from the Internet community. Welcome everyone to submit mr to perfect the possible influence surface. | ||
|
||
## Affect the internet manufacturer | ||
|
||
#### Apple | ||
![](internet/apple.jpg) | ||
![](internet/apple2.jpg) | ||
![](internet/apple3.jpg) | ||
![](internet/apple4.jpg) | ||
|
||
#### Tencent | ||
![](internet/Tencent.png) | ||
#### steam | ||
![](internet/steam.jpg) | ||
![](internet/twitter.png) | ||
#### Baidu | ||
![](internet/baidu.jpg) | ||
#### DIDI | ||
![](internet/didi.png) | ||
#### JD | ||
![](internet/JD.jpg) | ||
#### NetEase | ||
![](internet/NetEase.png) | ||
|
||
#### CloudFlare | ||
![](internet/CloudFlare.jpg) | ||
|
||
#### Amazon | ||
![](internet/amazon.jpg) | ||
|
||
#### Tesla | ||
![](internet/tesla.jpg) | ||
|
||
|
||
#### To be continued | ||
![](internet/Todo.jpg) | ||
|
||
## Affect the components | ||
|
||
#### Apache Solr | ||
![](components/solr/solr.jpg) | ||
|
||
#### Apache Druid | ||
![](components/Druid/Druid.jpg) | ||
|
||
#### Apache Flink | ||
|
||
#### Apache Struts2 | ||
![](components/Struts2/Struts2.jpg) | ||
|
||
#### flume | ||
|
||
#### dubbo | ||
|
||
#### IBM Qradar SIEM | ||
|
||
- /opt/qradar/support/mod_log4j.pl | ||
|
||
- [logging](https://www.ibm.com/mysupport/s/question/0D50z00006PEIeQCAX/qradar-qradarlog-and-qradarerror-slf4j-this-version-of-slf4j-requires-log4j-version-1212-or-later?language=en_US) | ||
|
||
|
||
#### PaloAlto Panorama | ||
|
||
- [logging](https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-10-0-open-source-software-oss-listing.html) | ||
|
||
|
||
|
||
#### Redis | ||
|
||
#### Elastic | ||
|
||
![](components/ElasticSearch/ElasticSearch.jpg) | ||
|
||
|
||
#### kafka | ||
|
||
#### ghidra | ||
![](components/ghidra/ghidra.jpg) | ||
|
||
|
||
#### ghidra server | ||
![](components/ghidra/ghidra_server.png) | ||
|
||
#### Minecraft | ||
![](components/Minecraft/Minecraft.jpg) | ||
|
||
|
||
#### PulseSecure | ||
- [KB44933 - CVE-2021-44228 - Java logging library (log4j)](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/KB44933/s) | ||
|
||
|
||
#### UniFi | ||
- [UniFi Network Application 6.5.54](https://community.ui.com/releases/UniFi-Network-Application-6-5-54/d717f241-48bb-4979-8b10-99db36ddabe1) | ||
|
||
#### VMWare | ||
|
||
- vCenter, vCloud | ||
|
||
- [kb.vmware.com/s/global-search/%40uri#q=Log4j](https://kb.vmware.com/s/global-search/%40uri#q=Log4j&t=MoreContent&sort=relevancy) | ||
- [VMware Response to CVE-2021-44228: Apache Log4j Remote Code Execution (87068)](https://kb.vmware.com/s/article/87068?lang=en_US) | ||
~~~ | ||
A critical vulnerability in Apache Log4j identified by CVE-2021-44228 | ||
has been disclosed that may allow for remote code execution. | ||
VMware has classified this issue as critical and is working on | ||
publishing fixes and workarounds as a priority. | ||
~~~ | ||
Log4j impact on manufacturers and components summary from the Internet community. If Manufacturer or Component is not verified, it does not have screenshots or references to prove that it is affected. | ||
|
||
## The List | ||
|
||
| Manufacturer/Component | Notes | Verified | | ||
| ---------------------------------------- | ----- | -------- | | ||
| [Apple](pages/apple.md) | | TRUE | | ||
| [Tencent](pages/Tencent.md) | | TRUE | | ||
| [Steam](pages/Steam.md) | | TRUE | | ||
| [Twitter](pages/Twitter.md) | | TRUE | | ||
| [Baidu](pages/Baidu.md) | | TRUE | | ||
| [DIDI](pages/DIDI.md) | | TRUE | | ||
| [JD](pages/JD.md) | | TRUE | | ||
| [NetEase](pages/NetEase.md) | | TRUE | | ||
| [CloudFlare](pages/CloudFlare.md) | | TRUE | | ||
| [Amazon](pages/Amazon.md) | | TRUE | | ||
| [Tesla](pages/Tesla.md) | | TRUE | | ||
| [Apache Solr](pages/ApacheSolr.md) | | TRUE | | ||
| [Apache Druid](pages/ApacheDruid.md) | | TRUE | | ||
| [Apache Flink](pages/ApacheFlink.md) | | FALSE | | ||
| [Apache Struts2](pages/ApacheStruts2.md) | | TRUE | | ||
| [flume](pages/flume.md) | | FALSE | | ||
| [dubbo](pages/dubbo.md) | | FALSE | | ||
| [IBM Qradar SIEM](pages/IBM.md) | | TRUE | | ||
| [PaloAlto Panorama](pages/PaloAlto.md) | | TRUE | | ||
| [Redis](pages/Redis.md) | | FALSE | | ||
| [logstash](pages/logstash.md) | | FALSE | | ||
| [ElasticSearch](pages/ElasticSearch.md) | | TRUE | | ||
| [kafka](pages/kafka.md) | | FALSE | | ||
| [ghidra](pages/ghidra.md) | | TRUE | | ||
| [ghidra server](pages/ghidraServer.md) | | TRUE | | ||
| [Minecraft](pages/Minecraft.md) | | TRUE | | ||
| [PulseSecure](pages/PulseSecure.md) | | TRUE | | ||
| [UniFi](pages/UniFi.md) | | TRUE | | ||
| [VMWare](pages/VMWare.md) | | TRUE | |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
## Description | ||
|
||
## Evidence | ||
![](../internet/amazon.jpg) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
## Description | ||
|
||
## Evidence | ||
![](../components/Druid/Druid.jpg) | ||
|
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
## Description | ||
|
||
## Evidence | ||
- /opt/qradar/support/mod_log4j.pl | ||
|
||
- [logging](https://www.ibm.com/mysupport/s/question/0D50z00006PEIeQCAX/qradar-qradarlog-and-qradarerror-slf4j-this-version-of-slf4j-requires-log4j-version-1212-or-later?language=en_US) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
## Description | ||
|
||
## Evidence | ||
- [logging](https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-10-0-open-source-software-oss-listing.html) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
## Description | ||
|
||
## Evidence | ||
- [KB44933 - CVE-2021-44228 - Java logging library (log4j)](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/KB44933/s) | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
## Description | ||
|
||
## Evidence | ||
- [UniFi Network Application 6.5.54](https://community.ui.com/releases/UniFi-Network-Application-6-5-54/d717f241-48bb-4979-8b10-99db36ddabe1) | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
## Description | ||
|
||
## Evidence | ||
|
||
- vCenter, vCloud | ||
|
||
- [kb.vmware.com/s/global-search/%40uri#q=Log4j](https://kb.vmware.com/s/global-search/%40uri#q=Log4j&t=MoreContent&sort=relevancy) | ||
- [VMware Response to CVE-2021-44228: Apache Log4j Remote Code Execution (87068)](https://kb.vmware.com/s/article/87068?lang=en_US) | ||
~~~ | ||
A critical vulnerability in Apache Log4j identified by CVE-2021-44228 | ||
has been disclosed that may allow for remote code execution. | ||
VMware has classified this issue as critical and is working on | ||
publishing fixes and workarounds as a priority. | ||
~~~ | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
## Description | ||
|
||
## Evidence | ||
|
||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
## Description | ||
|
||
## Evidence | ||
|
||
![](../components/ghidra/ghidra_server.png) |
Binary file not shown.