ã¯ããã« ããã«ã¡ã¯ãä¹ ã ã«å¯åããããã¦å¹ãã§ããSSTç ç©¶éçºé¨ã®å°ééã§ããä»å¹´å ¥ã£ã¦ããæ°äººãããã¡ã¯ãç§ã®ããã«ãªããªãã§ã»ããã¨ç¥ãã°ããã§ãã ãã¦ãæ°å¹´åº¦ã«ã¯å ¥ã£ã¦ãã¾ãã¾ããããã¤ãå æ¥ã¾ã§2021年度æ°åç ä¿®æå¾ã®å»¶é·æ¦ã¨ãã¦ã以å話é¡ã«ãªã£ãLog4Shellèå¼±æ§ã®PoCãä½ãã¨ãã課é¡ã«åãçµãã§ãã¾ããããã£ã¨åä½ããã¨ããã¾ã§ãã£ããã®ã®ãããã¾ã§ã®éã®ãã¯éå¸¸ã«æã¦ããªãè¤éã§é·ãéºãããã®ã§ããã ã»ãã¥ãªãã£æ¥çã«ããã¦ãå¤ãã®å ´åèå¼±æ§ã®è©³ç´°ãªåç¾æé ã¯ä¼ããããå¾åã«ããã¾ããããã¯ä¸»ã«æªç¨ãé²ããããªã®ã§ãããã»ãã¥ãªãã£ã®åå¦è ã«ã¯å®éã®æä½ãã©ãããã¨ã©ãå±ãªãã®ããåããã¥ããå ´åãå¤ãã®ãç¾ç¶ã§ãã Log4Shellèå¼±æ§ã¯é常ã«å¤§ããªé¨ãã«ãªã£ããããåæã®å¯¾å¿ãæ©ãã£ããã¨æãã¾ããããã§ãæ¯è¼çLog4Shellã®å½±é¿ãè½ã¡çãã¦ã
LINEæ ªå¼ä¼ç¤¾ã¯ã2023å¹´10æ1æ¥ã«LINEã¤ãã¼æ ªå¼ä¼ç¤¾ã«ãªãã¾ãããLINEã¤ãã¼æ ªå¼ä¼ç¤¾ã®æ°ããããã°ã¯ãã¡ãã§ãã LINEã¤ãã¼ Tech Blog ããã«ã¡ã¯ãOpen Source Program Office TF (ã¿ã¹ã¯ãã©ã¼ã¹)ã§ããç§ãã¡ã¯LINEã®ã¨ã³ã¸ãã¢çµç¹ã¨ãªã¼ãã³ã½ã¼ã¹ã¨ã³ã·ã¹ãã ãèåãããã坿¥ãªé¢ä¿ãç¯ãã¦ã³ãã¥ããã£ã¨å ±ã«æé·ã§ããæåãä½ãããã«æ§ã ãªåãçµã¿ãè¡ã£ã¦ãã¾ããä»åã¯ããã®3æã«LINEãApache Software Foundationã®Silver Sponsorã«å ãããã¨ã«ãªã£ãèæ¯ã«ã¤ãã¦ç´¹ä»ãã¾ãã Apache Software Foundationã«ã¤ã㦠Apache Software Foundation (ASF)ã¯ããªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ãéçºã«å¿ è¦ãªè³æºãæ¯æ´ããããã«1999å¹´ã«ç±³å½ã§è¨ç«ããã
ç±³ãã¤ãã³æ¿æ¨©ããLog4jãåé¡ãªã©ãåãGAFAãOpenSSFãªã©ãæããOSSã»ãã¥ãªãã£ä¼è°éå¬ ç±³é£é¦æ¿åºã¯1æ13æ¥ï¼ç¾å°æéï¼ãAppleãGoogleãAmazonãªã©ããããããã°ããã¯ã¨ãªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ï¼OSSï¼çµç¹ã®ããããæãããµã¤ãã¼ã»ãã¥ãªãã£ä¼è°ãéå¬ããã2021å¹´12æã«çºè¦ãããLog4jã®èå¼±æ§ã奿©ã«ç·æ¥ã§éå¬ã決ã¾ã£ããã®ã ã åå 伿¥ããã³çµç¹ã¯ãAkamaiãAmazonãApache Software FoundationãAppleãCloudflareãMetaï¼æ§Facebookï¼ãGitHubãGoogleãIBMãLinux FoundationãOpen Source Security FoundationãMicrosoftãOracleãRedHatãVMWareãOracleã¯Log4jã©ã¤ãã©ãªãå®è¡ãããJa
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã Googleã¨IBMã¯ããªã¼ãã³ã½ã¼ã¹ã®ã»ãã¥ãªãã£ã®æ¸å¿µã«ã¤ãã¦ãã¯ã¤ããã¦ã¹ãéå¬ããä¼åã«åå å¾ãéè¦ãªãªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ããç¹å®ããããã«ãITçµç¹ãååããããã«å¼ã³ãããã ãã¯ã¤ããã¦ã¹ã®ãµã¤ãã¼ã»ãã¥ãªãã£æ å½ãªã¼ãã¼Anne Neubergeræ°ã主å°ãããã®ä¼åã«ã¯ãApacheãGoogleãAppleãAmazonãIBMãMicrosoftãMetaï¼æ§Facebookï¼ãLinuxãOracleã¨ãã£ãçµç¹ããç±³å½é²çãç±³ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã¤ã³ãã©ã»ãã¥ãªãã£åºï¼CISAï¼ãªã©ã®æ¿åºæ©é¢ãããé¢ä¿è ãåå ãããä»åã®ä¼åã¯ã2021å¹´12æã«çºè¦ããã¦ä»¥æ¥ãæ¸å¿µããã¦ãããApache Log4jã
Javaåããã°åºåã©ã¤ãã©ãªãApache Log4jãï¼Log4jï¼ã§12æ10æ¥ã«å¤æããèå¼±æ§ãå·¡ããä¸å½ã®è¡æ¿æ©é¢ã§ããä¸å½å·¥æ¥æ å ±åé¨ã¯ãã®ã»ã©ãææºé¢ä¿ã«ããã¢ãªã¯ã©ã¦ãï¼é¿éé²ï¼ãèå¼±æ§æ å ±ãçºè¦å¾ããã«å ±åããªãã£ãã¨ãã¦6ã«æéã®ææºåæ¢å¦åã¨ãããä¸å½ã®å ±éæ©é¢ã»21ä¸ç´çµæ¸å ±éã23æ¥å ±ããã åé¡ã¨ãªã£ã¦ããLog4jã®èå¼±æ§ã¯ãã¢ãªã¯ã©ã¦ããçºè¦ããã¨ããã¦ãããä¸å½å·¥æ¥æ å ±åé¨ã»ãããã¯ã¼ã¯å®å ¨ç®¡çå±ã¯ãå社ããã®èå¼±æ§ãç±³Apache Software Foundationï¼ASFï¼ã«å ±åãã䏿¹ã§ãåå±ã«ã¯ããã«å ±åããªãã£ãã¨ãã¦ãããåå±ã¯å¥ã®æ å ±ã»ãã¥ãªãã£æ©é¢ãããã®èå¼±æ§ã®å ±åãåããASFã«ä¿®æ£ãä¿ããã¨ããã ä¸å½ã¯ããããã¯ã¼ã¯å®å ¨æ³ãã®ç¬¬25æ¡ã§ããããã¯ã¼ã¯äºæ¥è ã¯èå¼±æ§ãªã©æ å ±ã»ãã¥ãªãã£ä¸ã®ãªã¹ã¯ãçºçããå ´åãç·æ¥å¯¾å¿ãç´ã¡ã«éå§
christine.websiteã®ããã°ããã ã¾ãã¯: ãéãæããªãéããæç¨ãªã½ããã¦ã§ã¢ãæ¸ããªãã®ã? æè¿ãéè¦ãªJavaã¨ã³ã·ã¹ãã ã»ããã±ã¼ã¸ã«å¤§ããªèå¼±æ§ãè¦ã¤ããã¾ããããã®èå¼±æ§ãå®å ¨ã«å µå¨åãããã¨ãæ»æè ã¯LDAPãµã¼ãããåå¾ããä»»æã®ã³ã¼ããå®è¡ãããããJavaãµã¼ããå¼·å¶ãããã¨ãã§ãã¾ãã <ãã©> ããããããã¥ã¼ã¹ã§ãããªããJavaã·ã§ããã§åãã¦ãããªããæ®å¿µã§ãããããªãã«ã¯2ã3æ¥ãå¾ ã£ã¦ãã¾ãã ç§ã¯ããããããªã¼ãã³ã½ã¼ã¹ãã½ããã¦ã§ã¢ã®ä¸»è¦ãªã¨ã³ã·ã¹ãã åé¡ã®å ¨ã¦ã®å®ç§ãªç¸®å³ã ã¨èãã¦ãã¾ããlog4j2ãããã®åé¡ã®ææªã®ã·ããªãªã®1ã¤ã®å®ç§ãªä¾ã§ããã¨æãã®ã§ããã®ãã¹ã¦ã«ã¤ãã¦ããã¤ãèããæã£ã¦ãã¾ãããã®åé¡ã«é¢ä¸ãããã¹ã¦ã®äººããç¾å®ä¸çã®åé¡ã«å¯¾ããå®å ¨ã«å¦¥å½ãªè§£æ±ºçã®ããã«ããããã¹ã¦ãè¡ã£ããã¨ã¯å®å ¨ã«åççã§ããã
JPCERT-AT-2021-0050 JPCERT/CC 2021-12-11ï¼æ°è¦ï¼ 2022-01-04ï¼æ´æ°ï¼ I. æ¦è¦ æ´æ°: 2022å¹´1æ4æ¥è¨è¼ ç¾æç¹ã§ä¸æãªç¹ããããã¨ãããä»å¾ã®å忬¡ç¬¬ã§ä¸è¨æ²è¼å 容ãä¿®æ£ãæ´æ°ããäºå®ãããã¾ãã®ã§ãé¢é£æ å ±ã¸ã®æ³¨è¦ã®ã»ããæ¬æ³¨æåèµ·ã®æ´æ°å 容ã鿬¡ã確èªãã ããã æ¬¡ã®æ´æ°ãè¡ãã¾ããã詳細ã¯ãIII. 対çããåç §ãã¦ãã ããã - Apache Log4jã®ãã¼ã¸ã§ã³2.17.1ï¼Java 8以éã®ã¦ã¼ã¶ã¼åãï¼ã2.12.4ï¼Java 7ã®ã¦ã¼ã¶ã¼åãï¼åã³2.3.2ï¼Java 6ã®ã¦ã¼ã¶ã¼åãï¼ãå ¬éããã¾ãã Javaãã¼ã¹ã®ãªã¼ãã³ã½ã¼ã¹ã®ãã®ã³ã°ã©ã¤ãã©ãªã®Apache Log4jã«ã¯ãä»»æã®ã³ã¼ãå®è¡ã®èå¼±æ§ï¼CVE-2021-44228ï¼ãããã¾ããApache Log4jãåä½ãããµã¼ãã¼ã«ããã¦ãé éã®ç¬¬ä¸
log4jã¨ã¯Javaç¨ã®loggingã©ã¤ãã©ãªã ãloggingã©ã¤ãã©ãªã¨ããã®ã¯ãã°ã¨ãã¦è¨é²ãã¹ãæååãåãåãããããã©ããã«åºåãããã®ã ãæååã®ä¸èº«ãé常ã®loggingã©ã¤ãã©ãªã¯æ°ã«ããªãã log4jãé常ã®loggingã©ã¤ãã©ãªã¨éãã®ã¯ãæååã®ä¸èº«ãè¦ã¦ãä¸é¨ã®æååã夿°ã¨ã¿ãªãã¦ç½®æãããã¨ã ãããã¯log4jã®ããã¥ã¡ã³ãã§ã¯lookupã¨å¼ã°ãã¦ããã Log4j â Log4j 2 Lookups ä¾ãã°ããã°ã©ã ãå®è¡ä¸ã®Java runtimeã®ãã¼ã¸ã§ã³ããã°ã«å«ãããå ´åã¯ã"Java Runtime: ${java:runtime}"ãªã©ã¨ããã¨ã"Java Runtgime: Java(TM) SE Runtime Environment (build 1.7.0_67-b01) from Oracle Corporation"ãªã©ã®
2015-11-12 追è¨ããããSpringã¨Groovyã«ãç´ååãªãã¸ã§ã¯ãèå¼±æ§ããåç §ãã¦ãã ããã æ¨æ¥ããJavaçéã§è©±é¡ã«ãªã£ã¦ããcommons-collectionsã®èå¼±æ§ã«ã¤ãã¦ã å ãã¿ã¯ãã¡ãã 対å¿ãããã±ããã¯ãã¡ãã InvokerTransformerãªãã¦ã¯ã©ã¹ã¯åãã¦ç¥ãã¾ããããããããããããã¨ã«ãªãã¾ããããâ¦ã¨ããã®ãææ³ã§ãã å½±é¿ãåããã·ã¹ãã InvokerTransformerã¯commons-collectionsã¨commons-collections4ã®ä¸¡æ¹ã«åå¨ãã¦ãã¾ãã ããããã®ã©ã¤ãã©ãª(commons-collections.jarã¾ãã¯commons-collections4.jar)ãã¯ã©ã¹ãã¹ã«åå¨ãã¦ããã¨ãã 以ä¸ã®ããããã®æ¡ä»¶ãæºããã¦ããã¨æ»æãæç«ããå¯è½æ§ãããã¾ãã ç´ååãããªãã¸ã§ã¯ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}