Forum Discussion

hornunsm's avatar
hornunsm
Visitor
3 years ago

New CVE-2021-44832 - Remote Code Execution (RCE) for log4j

On December 28th a new vulnerability was found in log4j 2.17.0.  Is SoapUI 5.6.1 impacted by this vulnerability?

1 Reply

  • KarelHusa's avatar
    KarelHusa
    Champion Level 3

    Hi hornunsm ,

    SoapUI 5.6.1 uses log4j 2.16.0 and thus is theoretically vulnerable to CVE-2021-44832. See https://logging.apache.org/log4j/2.x/security.html for more information.

     

    Hoewever, the attacker needs to modify the logging configuration, so you have to decide whether this applies to your situation. By default there is no JDBC Appender in the SoapUI's logging configuration.

     

    Log4j is now under heavy investigation, therefore different vulnerabilities come to light. Please note that SoapUI uses 150 Java libraries, they will have their vulnerabilities as well. Furthermore, SoapUI offers including custom Groovy code, which also can be misused for attacks. 

     

    Security needs to be taken more seriously than in the past, that's the main log4shell lesson. On the other hand (almost) every piece of software has its vulnerabilities, so we need to stay calm and think of security. If we want to be 100% secure we have to stop using computers at all. 🙂

     

    Best regards,

    Karel