¤ýHOME > °í°´¼¾ÅÍ > º¸¾È°øÁö
Apache Log4j º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í(³»¿ë Ãß°¡, KrCERT)
Log4j 2¹öÀü ¿Ü 1¹öÀü¿¡¼µµ º¸¾ÈÃë¾àÁ¡ÀÌ È®ÀÎµÇ¾î º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í µå¸³´Ï´Ù.
Âü°í URL: https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=36389
¡à °³¿ä
o Apache ¼ÒÇÁÆ®¿þ¾î Àç´ÜÀº ÀÚ»çÀÇ Log4j 2¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í[1]
o °ø°ÝÀÚ´Â ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¾Ç¼ºÄÚµå °¨¿° µîÀÇ ÇÇÇØ¸¦ ¹ß»ý½Ãų¼ö ÀÖÀ¸¹Ç·Î, ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í
¡Ø °ü·Ã »çÇ×Àº Âü°í»çÀÌÆ® [6] Ãë¾àÁ¡ ´ëÀÀ°¡À̵带 Âü°í ¹Ù¶ø´Ï´Ù.
¡Ø Âü°í »çÀÌÆ® [4]¸¦ È®ÀÎÇÏ¿© ÇØ´ç Á¦Ç°À» ÀÌ¿ë ÁßÀÏ °æ¿ì, ÇØ´ç Á¦Á¶»çÀÇ ±Ç°í¿¡ µû¶ó ÆÐÄ¡ ¶Ç´Â ´ëÀÀ ¹æ¾È Àû¿ë
¡à ÁÖ¿ä ³»¿ë
o
¡à ¿µÇâÀ» ¹Þ´Â ¹öÀü
o CVE-2021-44228
- 2.0-beta9 ~ 2.14.1 ¹öÀü (Log4j 2.12.2 Á¦¿Ü)
o CVE-2021-45046
- 2.0-beta9 ~ 2.12.1 ¹× 2.13.0 ~ 2.15.0 ¹öÀü
o CVE-2021-4104
- 1.2 ¹öÀü
¡Ø JMSAppender¸¦ »ç¿ëÇÏÁö ¾Ê´Â °æ¿ì Ãë¾àÁ¡ ¿µÇâ ¾øÀ½
¡Ø log4j 1.x¹öÀü »ç¿ëÀÚÀÇ °æ¿ì Ãß°¡ÀûÀÎ ¾÷±×·¹À̵å Áö¿ø ÁßÁö·Î ÀÎÇØ ´Ù¸¥ º¸¾ÈÀ§Çù¿¡ ³ëÃâµÉ °¡´É¼ºÀÌ ³ô¾Æ ÃֽŹöÀü ¾÷µ¥ÀÌÆ® Àû¿ë ±Ç°í
¡à ´ëÀÀ¹æ¾È
o Á¦Á¶»ç ȨÆäÀÌÁö¸¦ ÅëÇØ ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë[3]
¡Ø Á¦Á¶»ç ȨÆäÀÌÁö¿¡ ½Å±Ô¹öÀüÀÌ °è¼Ó ¾÷µ¥ÀÌÆ®µÇ°í ÀÖ¾î È®ÀÎ ÈÄ ¾÷µ¥ÀÌÆ® Àû¿ë ÇÊ¿ä
¡Ø ½Å±Ô ¾÷µ¥ÀÌÆ®°¡ ºÒ°¡ÇÒ °æ¿ì ÀÓ½ÃÁ¶Ä¡¹æ¾È Àû¿ë ±Ç°í
- CVE-2021-44228, CVE-2021-45046
¡¤ Java 8 : Log4j 2.16.0À¸·Î ¾÷µ¥ÀÌÆ®[3]
¡¤ Java 7 : Log4j 2.12.2À¸·Î ¾÷µ¥ÀÌÆ®[9]
¡¤ ÀÓ½ÃÁ¶Ä¡¹æ¾È : JndiLookup Ŭ·¡½º¸¦ °æ·Î¿¡¼ Á¦°Å : zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class
¡Ø ÀÓ½ÃÁ¶Ä¡¹æ¾ÈÀº °Ô½ÃµÈ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀÓ½ÃÀû Á¶Ä¡·Î ½Å±Ô ¹öÀüÀ¸·Î ¾÷±×·¹À̵带 ±ÇÀåÇÔ
¡Ø log4j-core JAR ÆÄÀÏ ¾øÀÌ log4j-api JAR ÆÄÀϸ¸ »ç¿ëÇÏ´Â °æ¿ì À§ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÁö ¾ÊÀ½
- CVE-2021-4104
¡¤ Java 8 : Log4j 2.16.0À¸·Î ¾÷µ¥ÀÌÆ®[3]
¡¤ Java 7 : Log4j 2.12.2À¸·Î ¾÷µ¥ÀÌÆ®[9]
[Âü°í»çÀÌÆ®]
[1] apache º¸¾È¾÷µ¥ÀÌÆ® ÇöȲ : https://logging.apache.org/log4j/2.x/security.html
[2] Ãë¾àÁ¡ Á¤º¸ : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
[3] ½Å±Ô¹öÀü ´Ù¿î·Îµå : https://logging.apache.org/log4j/2.x/download.html
[4] Á¦Á¶»çº° ÇöȲ : https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
[5] ŽÁöÁ¤Ã¥ : https://rules.emergingthreatspro.com/open/suricata-5.0/rules/emerging-exploit.rules
[6] Ãë¾àÁ¡ ´ëÀÀ °¡À̵å : https://www.boho.or.kr/data/guideView.do?bulletin_writing_sequence=36390
[7] Ãë¾àÁ¡ Á¤º¸ : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046
[8] Ãë¾àÁ¡ Á¤º¸ : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104
[9] Log4j 2.12.2¹öÀü ´Ù¿î·Îµå : https://archive.apache.org/dist/logging/log4j/2.12.2/