º»¹® ¹Ù·Î°¡±â
ÁÖ¸Þ´º ¹Ù·Î°¡±â
ÇÏ´ÜÁ¤º¸ ¹Ù·Î°¡±â

KT IDC ·Î°í


°í°´Áö¿ø : °í°´ÀÇ °æÀï·ÂÀ» °¡Àå ¼ÒÁßÇÏ°Ô »ý°¢ÇÕ´Ï´Ù.

olleh ±â¾÷°í»ö¼¾ÅÍ

TEL. 1588-0114

Àü±¹ ICC ÀüÈ­¹øÈ£ ¾È³»


¤ýHOME > °í°´¼¾ÅÍ > º¸¾È°øÁö

º¸¾È°øÁö

[º¸¾È°øÁö]Apache logj4 2 Ãë¾àÁ¡ °øÁö

  • µî·ÏÀÏ2021-12-13
  • Á¶È¸¼ö478
  • ÆÄÀÏ

Apache Log4j 2 º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í 2021.12.11(Ãâó : KR CERT)

 ¡à °³¿ä
   o Apache ¼ÒÇÁÆ®¿þ¾î Àç´ÜÀº ÀÚ»çÀÇ Log4j 2¿¡¼­ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í
   o °ø°ÝÀÚ´Â ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¾Ç¼ºÄÚµå °¨¿° µîÀÇ ÇÇÇØ¸¦ ¹ß»ý½Ãų¼ö ÀÖÀ¸¹Ç·Î, ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í
      - https://logging.apache.org/log4j/2.x/security.html


 ¡à ÁÖ¿ä ³»¿ë

    o Apache Log4j 2*¿¡¼­ ¹ß»ýÇÏ´Â ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡(CVE-2021-44228)
       * ÇÁ·Î±×·¥ ÀÛ¼º Áß ·Î±×¸¦ ³²±â±â À§ÇØ »ç¿ëµÇ´Â ÀÚ¹Ù ±â¹ÝÀÇ ¿ÀǼҽº À¯Æ¿¸®Æ¼
       - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228


 ¡à ¿µÇâÀ» ¹Þ´Â ¹öÀü

    o 2.0-beta9 ~ 2.14.1 ¸ðµç¹öÀü


 ¡à ÇØ°á ¹æ¾È

    o 2.0-beta9 ~ 2.10.0
      - JndLookup Ŭ·¡½º¸¦ °æ·Î¿¡¼­ Á¦°Å : zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class

    o 2.10 ~ 2.14.1
      - log4j2.formatMsgNoLookups ¶Ç´Â LOG4J_FORMAT_MSG_NO_LOOKUPS ȯ°æº¯¼ö¸¦ true·Î ¼³Á¤

     o Á¦Á¶»ç ȨÆäÀÌÁö¸¦ ÅëÇØ ÃֽŹöÀü(2.15.0)À¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë
      - https://logging.apache.org/log4j/2.x/download.html


 ¡à ±âŸ ¹®ÀÇ»çÇ×

     o Çѱ¹ÀÎÅͳÝÁøÈï¿ø »çÀ̹ö¹Î¿ø¼¾ÅÍ: ±¹¹ø¾øÀÌ 118

¸ñ·Ï

ÇÏ´Ü Á¤º¸