Skip to content

Commit

Permalink
Merge branch 'NovTangoPapa-master'
Browse files Browse the repository at this point in the history
  • Loading branch information
YfryTchsGD committed Dec 11, 2021
2 parents 2c2046d + ea09d47 commit c1c7bd5
Show file tree
Hide file tree
Showing 30 changed files with 90 additions and 107 deletions.
142 changes: 35 additions & 107 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,108 +1,36 @@
## Intro
Log4j impact manufacturers and components summary from the Internet community. Welcome everyone to submit mr to perfect the possible influence surface.

## Affect the internet manufacturer

#### Apple
![](internet/apple.jpg)
![](internet/apple2.jpg)
![](internet/apple3.jpg)
![](internet/apple4.jpg)

#### Tencent
![](internet/Tencent.png)
#### steam
![](internet/steam.jpg)
#### twitter
![](internet/twitter.png)
#### Baidu
![](internet/baidu.jpg)
#### DIDI
![](internet/didi.png)
#### JD
![](internet/JD.jpg)
#### NetEase
![](internet/NetEase.png)

#### CloudFlare
![](internet/CloudFlare.jpg)

#### Amazon
![](internet/amazon.jpg)

#### Tesla
![](internet/tesla.jpg)


#### To be continued
![](internet/Todo.jpg)

## Affect the components

#### Apache Solr
![](components/solr/solr.jpg)

#### Apache Druid
![](components/Druid/Druid.jpg)

#### Apache Flink

#### Apache Struts2
![](components/Struts2/Struts2.jpg)

#### flume

#### dubbo

#### IBM Qradar SIEM

- /opt/qradar/support/mod_log4j.pl

- [logging](https://www.ibm.com/mysupport/s/question/0D50z00006PEIeQCAX/qradar-qradarlog-and-qradarerror-slf4j-this-version-of-slf4j-requires-log4j-version-1212-or-later?language=en_US)


#### PaloAlto Panorama

- [logging](https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-10-0-open-source-software-oss-listing.html)



#### Redis

#### Elastic

![](components/ElasticSearch/ElasticSearch.jpg)


#### kafka

#### ghidra
![](components/ghidra/ghidra.jpg)


#### ghidra server
![](components/ghidra/ghidra_server.png)

#### Minecraft
![](components/Minecraft/Minecraft.jpg)


#### PulseSecure
- [KB44933 - CVE-2021-44228 - Java logging library (log4j)](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/KB44933/s)


#### UniFi
- [UniFi Network Application 6.5.54](https://community.ui.com/releases/UniFi-Network-Application-6-5-54/d717f241-48bb-4979-8b10-99db36ddabe1)

#### VMWare

- vCenter, vCloud

- [kb.vmware.com/s/global-search/%40uri#q=Log4j](https://kb.vmware.com/s/global-search/%40uri#q=Log4j&t=MoreContent&sort=relevancy)
- [VMware Response to CVE-2021-44228: Apache Log4j Remote Code Execution (87068)](https://kb.vmware.com/s/article/87068?lang=en_US)
~~~
A critical vulnerability in Apache Log4j identified by CVE-2021-44228
has been disclosed that may allow for remote code execution.
VMware has classified this issue as critical and is working on
publishing fixes and workarounds as a priority.
~~~
Log4j impact on manufacturers and components summary from the Internet community. If Manufacturer or Component is not verified, it does not have screenshots or references to prove that it is affected.

## The List

| Manufacturer/Component | Notes | Verified |
| ---------------------------------------- | ----- | -------- |
| [Apple](pages/apple.md) | | TRUE |
| [Tencent](pages/Tencent.md) | | TRUE |
| [Steam](pages/Steam.md) | | TRUE |
| [Twitter](pages/Twitter.md) | | TRUE |
| [Baidu](pages/Baidu.md) | | TRUE |
| [DIDI](pages/DIDI.md) | | TRUE |
| [JD](pages/JD.md) | | TRUE |
| [NetEase](pages/NetEase.md) | | TRUE |
| [CloudFlare](pages/CloudFlare.md) | | TRUE |
| [Amazon](pages/Amazon.md) | | TRUE |
| [Tesla](pages/Tesla.md) | | TRUE |
| [Apache Solr](pages/ApacheSolr.md) | | TRUE |
| [Apache Druid](pages/ApacheDruid.md) | | TRUE |
| [Apache Flink](pages/ApacheFlink.md) | | FALSE |
| [Apache Struts2](pages/ApacheStruts2.md) | | TRUE |
| [flume](pages/flume.md) | | FALSE |
| [dubbo](pages/dubbo.md) | | FALSE |
| [IBM Qradar SIEM](pages/IBM.md) | | TRUE |
| [PaloAlto Panorama](pages/PaloAlto.md) | | TRUE |
| [Redis](pages/Redis.md) | | FALSE |
| [logstash](pages/logstash.md) | | FALSE |
| [ElasticSearch](pages/ElasticSearch.md) | | TRUE |
| [kafka](pages/kafka.md) | | FALSE |
| [ghidra](pages/ghidra.md) | | TRUE |
| [ghidra server](pages/ghidraServer.md) | | TRUE |
| [Minecraft](pages/Minecraft.md) | | TRUE |
| [PulseSecure](pages/PulseSecure.md) | | TRUE |
| [UniFi](pages/UniFi.md) | | TRUE |
| [VMWare](pages/VMWare.md) | | TRUE |
4 changes: 4 additions & 0 deletions pages/Amazon.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
## Description

## Evidence
![](../internet/amazon.jpg)
5 changes: 5 additions & 0 deletions pages/ApacheDruid.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Description

## Evidence
![](../components/Druid/Druid.jpg)

Binary file added pages/ApacheFlink.md
Binary file not shown.
Binary file added pages/ApacheSolr.md
Binary file not shown.
Binary file added pages/ApacheStruts2.md
Binary file not shown.
Binary file added pages/Baidu.md
Binary file not shown.
Binary file added pages/CloudFlare.md
Binary file not shown.
Binary file added pages/DIDI.md
Binary file not shown.
Binary file added pages/ElasticSearch.md
Binary file not shown.
6 changes: 6 additions & 0 deletions pages/IBM.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
## Description

## Evidence
- /opt/qradar/support/mod_log4j.pl

- [logging](https://www.ibm.com/mysupport/s/question/0D50z00006PEIeQCAX/qradar-qradarlog-and-qradarerror-slf4j-this-version-of-slf4j-requires-log4j-version-1212-or-later?language=en_US)
Binary file added pages/JD.md
Binary file not shown.
Binary file added pages/Minecraft.md
Binary file not shown.
Binary file added pages/NetEase.md
Binary file not shown.
4 changes: 4 additions & 0 deletions pages/PaloAlto.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
## Description

## Evidence
- [logging](https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-10-0-open-source-software-oss-listing.html)
5 changes: 5 additions & 0 deletions pages/PulseSecure.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Description

## Evidence
- [KB44933 - CVE-2021-44228 - Java logging library (log4j)](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/KB44933/s)

Binary file added pages/Redis.md
Binary file not shown.
Binary file added pages/Steam.md
Binary file not shown.
Binary file added pages/Tencent.md
Binary file not shown.
Binary file added pages/Tesla.md
Binary file not shown.
Binary file added pages/Twitter.md
Binary file not shown.
5 changes: 5 additions & 0 deletions pages/UniFi.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Description

## Evidence
- [UniFi Network Application 6.5.54](https://community.ui.com/releases/UniFi-Network-Application-6-5-54/d717f241-48bb-4979-8b10-99db36ddabe1)

15 changes: 15 additions & 0 deletions pages/VMWare.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
## Description

## Evidence

- vCenter, vCloud

- [kb.vmware.com/s/global-search/%40uri#q=Log4j](https://kb.vmware.com/s/global-search/%40uri#q=Log4j&t=MoreContent&sort=relevancy)
- [VMware Response to CVE-2021-44228: Apache Log4j Remote Code Execution (87068)](https://kb.vmware.com/s/article/87068?lang=en_US)
~~~
A critical vulnerability in Apache Log4j identified by CVE-2021-44228
has been disclosed that may allow for remote code execution.
VMware has classified this issue as critical and is working on
publishing fixes and workarounds as a priority.
~~~

Binary file added pages/apple.md
Binary file not shown.
6 changes: 6 additions & 0 deletions pages/dubbo.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
## Description

## Evidence



Binary file added pages/flume.md
Binary file not shown.
Binary file added pages/ghidra.md
Binary file not shown.
5 changes: 5 additions & 0 deletions pages/ghidraServer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Description

## Evidence

![](../components/ghidra/ghidra_server.png)
Binary file added pages/kafka.md
Binary file not shown.
Binary file added pages/logstash.md
Binary file not shown.

0 comments on commit c1c7bd5

Please sign in to comment.