安全ID : QSA-21-58
Multiple Vulnerabilities in Apache Log4j Library
发布日期 : December 14, 2021
通用漏洞披露 : CVE-2021-44228 | CVE-2021-45046 | CVE-2021-45105 | CVE-2021-4104
受影响产品: QNAP NAS running certain applications
状态
已解决
Summary
Several vulnerabilities have been reported to affect the Apache Log4j Java logging library. If exploited, these vulnerabilities allow attackers to execute arbitrary code. The vulnerabilities were disclosed in December 2021:
- CVE-2021-44228: Apache Log4j 2 JNDI features do not protect against attacker-controlled LDAP and other JNDI related endpoints
- CVE-2021-45046: Apache Log4j 2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
- CVE-2021-45105: Apache Log4j 2 does not always protect from infinite recursion in lookup evaluation
- CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
We have determined that the QTS, QuTS hero, and QES operating systems are not affected.
For applications which depend on Java Runtime Environment, our findings are as follows.
Applications maintained by QNAP:
- Qsirch - Not affected
Applications maintained by a third-party provider:
- Tomcat (Adnovea) - Affected. Disabled in App Center.
- Tomcat8 (Adnovea) - Affected. Disabled in App Center.
- SuperSync iTunes Media Manager (SuperSync) - The vendor has not responded. Disabled in App Center.
- MinimServer (Simon Nash) - Not affected
- WorldCard Team (PenPower Technology Ltd.) - Not affected
- nConnect (NKN.org) - Not affected
Recommendation
For users running any of the applications that are affected by the vulnerabilities, we strongly recommend taking the following actions to protect your device:
- Stop the application temporarily.
- Do not expose your NAS to the internet, or avoid using default system port numbers 443 and 8080.
To fully secure your device, we highly recommend reading the following article: What is the best practice for enhancing NAS security?
Stopping an Application
- Log on to QTS or QuTS hero as administrator.
- Open the App Center and then click
.
A search box appears. - Enter the application name.
The application appears in the search results. - Click the arrow below the application icon and then select Stop.
QTS or QuTS hero stops the application.
Changing the System Port Number
- Log on to QTS or QuTS hero as administrator.
- Go to Control Panel > System > General Settings > System Administration.
- Specify a new system port number.
Warning: Do not use 443 or 8080. - Click Apply.
QTS or QuTS hero applies the new system port number.
修订历史:
V1.0 (December 14, 2021) - Published
V1.1 (December 15, 2021) - Update QES information
V1.2 (December 23, 2021) - Update WorldCard Team and nConnect
V2.0 (December 30, 2021) - Status updated