Release News PSA: Potential security vulnerability in Elasticsearch and more via Apache Log4j (Log4Shell)

  • Downloading from our site will require you to have a paid membership. Upgrade to a Premium Membership today!

    Dont forget read our Rules! Also anyone caught Sharing this content will be banned. By using this site you are agreeing to our rules so read them. Saying I did not know is simply not an excuse! You have been warned.

Radio

    Status
    Not open for further replies.

    ven0m

    Administrator
    Staff member
    Administrator
    Moderator
    Platinum
    xenForo 2.x.x
    xenForo 1.x.x
    Contributor
    vBulletin All Access Pass
    The Chest
    Verified
    Ultra Platinum VIP
    Platinum VIP
    Gold VIP
    Silver VIP
    Premium
    Member
    Jul 17, 2005
    20,500
    7,741
    321
    localhost
    It has come to our attention today that a vulnerability has been discovered in popular Java logging library Log4j 2 which may allow attackers to arbitrarily execute code (remote code execution).

    Apache Log4j 2 is bundled with and used in many Java applications including Elasticsearch.

    XenForo itself is not directly exploitable, and we are currently investigating whether XenForo Enhanced Search can be used as a vector at all, but this is potentially significant enough that an abundance of...

     
    Status
    Not open for further replies.
    Thread starter Similar threads Forum Replies Date
    ven0m Release News PSA: Solve Media CAPTCHA no longer functional and should be disabled Release & Add-on News 0
    ven0m Release News XenForo 2.3.7 Released (Includes Security Fixes) Release & Add-on News 0
    ven0m Release News XenForo 2.3.5 (Includes Security Fix) & Add-ons Released Release & Add-on News 0
    ven0m Release News XenForo 2.2.17 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.15, 2.2.16 and XenForo Media Gallery 2.1.9, 2.2.6 Released (Includes Security Fixes) Release & Add-on News 0
    ven0m Release News XenForo & Add-ons 2.3.0 Release Candidate 1 Released (Unsupported) (Includes Security Fixes) Release & Add-on News 0
    ven0m Release News XenForo 2.1.13 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.2.11 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.2.10 Released (Includes security fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.12 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.2.1 Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.2.1 Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.12 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.11 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.10 Patch 2 Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.10 Patch 1 Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.10 (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.9 and 2.0.13 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.1.7 (Includes Security Fix) and Media Gallery 2.1.7 Released Release & Add-on News 0
    ven0m Release News vBulletin Security Patch Released. Versions 5.5.2, 5.53, and 5.5.4 Release & Add-on News 0
    ven0m Release News XenForo 2.0.11 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.0.11 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.0.9 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 2.0.8 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 1.5.18 Released - Includes Security Fix Release & Add-on News 0
    ven0m Release News XenForo 2.0.3 Released - Includes Security Fix Release & Add-on News 0
    ven0m Release News XenForo 1.5.18 Released - Includes Security Fix Release & Add-on News 0
    ven0m Release News XenForo 2.0.3 Released - Includes Security Fix Release & Add-on News 0
    ven0m Release News Security Patch Released for vBulletin 5.3.2, 5.3.3, and 5.3.4 Release & Add-on News 0
    ven0m Release News Security Patch Released for vBulletin 5.3.2, 5.3.3, and 5.3.4 Release & Add-on News 0
    ven0m Release News Reminder: Account/Password Security Best Practices Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 5.2.2, 5.2.3 and 5.2.4 (Updated) Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 5.2.2, 5.2.3 and 5.2.4 (Updated) Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 5.2.2, 5.2.3 and 5.2.4 Release & Add-on News 0
    ven0m Release News Reminder: Account/Password Security Best Practices Release & Add-on News 0
    ven0m Release News XenForo 1.5.10a Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News XenForo Media Gallery 1.0.10 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 1.4.13 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 1.5.10 Released (Includes Security Fix) Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 5.2.0, 5.2.1, 5.2.2 Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 3.8.7, 3.8.8, 3.8.9, 3.8.10 Beta Release & Add-on News 0
    ven0m Release News Security Patch - vBulletin 4.2.2, 4.2.3, 4.2.4 Beta Release & Add-on News 0
    ven0m Release News XenForo 1.4.12 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 1.5.4 Released (Security Fix) Release & Add-on News 0
    ven0m Release News XenForo 1.3.10 Released (Security Fix) Release & Add-on News 0
    W Release News ImageMagick Security Issue Release & Add-on News 0
    P Release News Security Update for vBulletin 4 Release & Add-on News 0
    Similar threads