From 7669f4c03ff99964edf7df05231a744af9f4b61a Mon Sep 17 00:00:00 2001 From: "Mark J. Cox" Date: Tue, 18 Jan 2022 15:19:58 +0000 Subject: [PATCH] Logging --- 2022/23xxx/CVE-2022-23302.json | 92 +++++++++++++++++++++++++++++++--- 2022/23xxx/CVE-2022-23305.json | 92 +++++++++++++++++++++++++++++++--- 2022/23xxx/CVE-2022-23307.json | 92 +++++++++++++++++++++++++++++++--- 3 files changed, 252 insertions(+), 24 deletions(-) diff --git a/2022/23xxx/CVE-2022-23302.json b/2022/23xxx/CVE-2022-23302.json index cb2a182b9a8..fb11158b750 100644 --- a/2022/23xxx/CVE-2022-23302.json +++ b/2022/23xxx/CVE-2022-23302.json @@ -1,18 +1,94 @@ { - "data_type": "CVE", - "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { + "ASSIGNER": "security@apache.org", "ID": "CVE-2022-23302", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "STATE": "PUBLIC", + "TITLE": "Deserialization of untrusted data in JMSSink in Apache Log4j 1.x" }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "Apache Log4j 1.x", + "version": { + "version_data": [ + { + "version_affected": ">=", + "version_value": "1.0.1" + }, + { + "version_affected": "<", + "version_value": "2.0-alpha1" + } + ] + } + } + ] + }, + "vendor_name": "Apache Software Foundation" + } + ] + } + }, + "credit": [ + { + "lang": "eng", + "value": "Eduardo' Vela, Maksim Shudrak and Jacob Butler from Google." + } + ], + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. \n\nNote this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default.\n\nApache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions." } ] - } -} \ No newline at end of file + }, + "generator": { + "engine": "Vulnogram 0.0.9" + }, + "impact": [ + { + "other": "high" + } + ], + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-502 Deserialization of Untrusted Data" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "url": "https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w" + }, + { + "refsource": "MISC", + "url": "https://logging.apache.org/log4j/1.2/index.html" + } + ] + }, + "source": { + "discovery": "UNKNOWN" + }, + "work_around": [ + { + "lang": "eng", + "value": "Users should upgrade to Log4j 2 or remove usage of the JMSSink from their configurations." + } + ] +} diff --git a/2022/23xxx/CVE-2022-23305.json b/2022/23xxx/CVE-2022-23305.json index c62dff1647a..8021fc74117 100644 --- a/2022/23xxx/CVE-2022-23305.json +++ b/2022/23xxx/CVE-2022-23305.json @@ -1,18 +1,94 @@ { - "data_type": "CVE", - "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { + "ASSIGNER": "security@apache.org", "ID": "CVE-2022-23305", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "STATE": "PUBLIC", + "TITLE": "SQL injection in JDBC Appender in Apache Log4j V1" }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "Apache Log4j 1.x ", + "version": { + "version_data": [ + { + "version_affected": ">=", + "version_value": "1.2.1" + }, + { + "version_affected": "<", + "version_value": "2.0-alpha1" + } + ] + } + } + ] + }, + "vendor_name": "Apache Software Foundation" + } + ] + } + }, + "credit": [ + { + "lang": "eng", + "value": "Daniel Martin of NCC Group" + } + ], + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed.\n\nNote this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs.\n\nApache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions." } ] - } -} \ No newline at end of file + }, + "generator": { + "engine": "Vulnogram 0.0.9" + }, + "impact": [ + { + "other": "high" + } + ], + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "url": "https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y" + }, + { + "refsource": "MISC", + "url": "https://logging.apache.org/log4j/1.2/index.html" + } + ] + }, + "source": { + "discovery": "UNKNOWN" + }, + "work_around": [ + { + "lang": "eng", + "value": "Users should upgrade to Log4j 2 or remove usage of the JDBCAppender from their configurations." + } + ] +} diff --git a/2022/23xxx/CVE-2022-23307.json b/2022/23xxx/CVE-2022-23307.json index c85b2262c5d..1071066c2ed 100644 --- a/2022/23xxx/CVE-2022-23307.json +++ b/2022/23xxx/CVE-2022-23307.json @@ -1,18 +1,94 @@ { - "data_type": "CVE", - "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { + "ASSIGNER": "security@apache.org", "ID": "CVE-2022-23307", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "STATE": "PUBLIC", + "TITLE": " A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution." }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "Apache Log4j 1.x", + "version": { + "version_data": [ + { + "version_affected": ">=", + "version_value": "1.2.1" + }, + { + "version_affected": "<=", + "version_value": "2.0-alpha1" + } + ] + } + } + ] + }, + "vendor_name": "Apache Software Foundation" + } + ] + } + }, + "credit": [ + { + "lang": "eng", + "value": "@kingkk" + } + ], + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists." } ] - } -} \ No newline at end of file + }, + "generator": { + "engine": "Vulnogram 0.0.9" + }, + "impact": [ + { + "other": "Critical" + } + ], + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-502 Deserialization of Untrusted Data" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "refsource": "CONFIRM", + "url": "https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh" + }, + { + "refsource": "MISC", + "url": "https://logging.apache.org/log4j/1.2/index.html" + } + ] + }, + "source": { + "discovery": "UNKNOWN" + }, + "work_around": [ + { + "lang": "eng", + "value": "Upgrade to Apache Log4j 2 and Apache Chainsaw 2.1.0." + } + ] +}