¾È³çÇϼ¼¿ä. À¥ÇÁ¶óÀÓ(ÁÖ) ÀÔ´Ï´Ù. Apache ¼ÒÇÁÆ®¿þ¾î Log4j 2¿¡¼ ¸Å¿ì Áß´ëÇÑ Ãë¾àÁ¡ÀÌ ¹ß°ß µÇ¾ú½À´Ï´Ù. ¾Æ·¡ KISA ±Ç°í¹®À» Âü°íÇÏ¿© ºü¸£°Ô Á¶Ä¡ ÇÏ½Ã±æ ±Ç°í µå¸³´Ï´Ù.
====================== ÀÌÇÏ ¾Æ·¡ ³»¿ë KISA º¸¾È ±Ç°í¹® Àü¹®====================== ¡à °³¿ä o Apache ¼ÒÇÁÆ®¿þ¾î Àç´ÜÀº ÀÚ»çÀÇ Log4j 2¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í[1] o °ø°ÝÀÚ´Â ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¾Ç¼ºÄÚµå °¨¿° µîÀÇ ÇÇÇظ¦ ¹ß»ý½Ãų¼ö ÀÖÀ¸¹Ç·Î, ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í
¡à ÁÖ¿ä ³»¿ë o Apache Log4j 2*¿¡¼ ¹ß»ýÇÏ´Â ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡(CVE-2021-44228)[2] * ÇÁ·Î±×·¥ ÀÛ¼º Áß ·Î±×¸¦ ³²±â±â À§ÇØ »ç¿ëµÇ´Â ÀÚ¹Ù ±â¹ÝÀÇ ¿ÀǼҽº À¯Æ¿¸®Æ¼
¡à ¿µÇâÀ» ¹Þ´Â ¹öÀü o Apache Log4j 2 - 2.0-beta9 ~ 2.14.1 ¸ðµç¹öÀü o Apache Log4j 2¸¦ »ç¿ëÇÏ´Â Á¦Ç° ¡Ø Âü°í »çÀÌÆ® [4]¸¦ È®ÀÎÇÏ¿© ÇØ´ç Á¦Ç°À» ÀÌ¿ë ÁßÀÏ °æ¿ì, ÇØ´ç Á¦Á¶»çÀÇ ±Ç°í¿¡ µû¶ó ÆÐÄ¡ ¶Ç´Â ´ëÀÀ ¹æ¾È Àû¿ë ¡à ÇØ°á¹æ¾È[1] o 2.0-beta9 ~ 2.10.0 - JndiLookup Ŭ·¡½º¸¦ °æ·Î¿¡¼ Á¦°Å : zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class o 2.10 ~ 2.14.1 - log4j2.formatMsgNoLookups ¶Ç´Â LOG4J_FORMAT_MSG_NO_LOOKUPS ȯ°æº¯¼ö¸¦ true·Î ¼³Á¤ o Á¦Á¶»ç ȨÆäÀÌÁö¸¦ ÅëÇØ ÃֽŹöÀü(2.15.0)À¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë[3]
¡à ±âŸ ¹®ÀÇ»çÇ× o Çѱ¹ÀÎÅͳÝÁøÈï¿ø »çÀ̹ö¹Î¿ø¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®] [1] https://logging.apache.org/log4j/2.x/security.html [2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228 [3] https://logging.apache.org/log4j/2.x/download.html [4] https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
¡à ÀÛ¼º : ħÇØ»ç°íºÐ¼®´Ü Ãë¾àÁ¡ºÐ¼®ÆÀ
|