[RSS Feed/News] PSA: Potential security vulnerability in Elasticsearch and more via Apache Log4j (Log4Shell)

Status
Not open for further replies.

XenForo

Administrative
  • Thread starter
  • Admin
  • #1
It has come to our attention today that a vulnerability has been discovered in popular Java logging library Log4j 2 which may allow attackers to arbitrarily execute code (remote code execution).

Apache Log4j 2 is bundled with and used in many Java applications including Elasticsearch.

XenForo itself is not directly exploitable, and we are currently investigating whether XenForo Enhanced Search can be used as a vector at all, but this is potentially significant enough that an abundance of...

Read more

ادامه مطلب...
 
Status
Not open for further replies.
Back
Top Bottom