Subsonic uses log4j, which is vulnerable and actively exploited.
https://arstechnica.com/information-tec ... ution-bug/
Is there a patched version available?
Moderator: moderators
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
Can somebody translate this for me, mybe with a practical example?
acroyear wrote:Of note, Navidrome only supports ID3 tagging...
molokoplus wrote:I was curious about this, as well.
I will be looking into airsonic, thanks for the heads up.
I do have to say, though, I just looked in the war file of the latest/last version of Subsonic I have installed, and it is using Log4J 1.2.16, which is not vulnerable to Log4Shell, but is vulnerable to its own nasty item, but maybe not quite as readily and easily exploitable as jndi access: https://cve.mitre.org/cgi-bin/cvename.c ... 2019-17571
Users browsing this forum: No registered users and 8 guests