Is Digital Theatre+ vulnerable to CVE-2021-44228 (Apache Log4j2)?
This article provides detail on why Digital Theatre+ is not affected by this vulnerability
A critical zero-day vulnerability in Apache log4j2 <=2.14.1 was identified by Chen Zhaojun of Alibaba Cloud Security Team and reported by the project Thursday 9 December 2021. The vulnerability allows a remote, unauthenticated attacker to achieve Remote Code Execution (RCE) on any affected system by sending a single crafted payload string.
More information about the vulnerability can be found on the Common Vulnerabilities and Exposures (CVE) website entry for CVE-2021-44228
What is Log4j?
Log4j 2 is a popular Java logging framework developed by the Apache Software Foundation.
Digital Theatre+
Digital Theatre+ uses components from a number of major cloud providers. We have assessed each component against CVE-2021-44228 and are satisfied that our platform is not exposed to this vulnerability. Digital Theatre+ is satisfied that our platform is not exposed to this vulnerability.
All of the code created and hosted by Digital Theatre+ uses JavaScript, TypeScript, Node.js and Next.js, with associated JavaScript libraries. This means none of the code written by Digital Theatre+ is affected by the Log4Shell vulnerability, which impacts only Java-based applications using the Log4j 2 library.
Following is a list of the major components of our system with reference to vulnerability statements:
AWS Lambda
AWS Lambda does not include Log4j2 in its managed runtimes or base container images.
AWS API Gateway
AWS has updated API Gateway to use a patched version of Log4j2 that mitigates CVE-2021-44228. For the latest status, refer to the AWS Security Bulletin (AWS-2021-006).
AWS CloudFront
CloudFront services have been updated to mitigate the issues identified in CVE-2021-44228. The CloudFront request handling services that run in our POPs are not written in Java and therefore were not affected by this issue.
AWS RDS
RDS-built relational database engines do not include the Apache Log4j library.
AWS DynamoDB
Amazon DynamoDB and Amazon DynamoDB Accelerator (DAX) have been updated to mitigate the issues identified in CVE-2021-44228.
AWS OpenSearch
Amazon OpenSearch Service was updated with service software version R20211203-P2, which contains a patched version of Log4j2 addressing CVE-2021-44228. This update has been applied globally. Digital Theatre+ is comfortable with this, as only content information is stored in OpenSearch.
Okta
Okta has confirmed that the products and components used by Digital Theatre+ are not affected.
Cloudflare
Cloudflare has confirmed that they have completed remediation steps and do not believe their platform was compromised.
Contentful
Contentful's security team confirmed that Contentful is not using log4j in their platform. All Contentful's logging pipelines utilise another solution for log collection.
References
https://www.cve.org/CVERecord?id=CVE-2021-44228
https://aws.amazon.com/security/security-bulletins/AWS-2021-006/
https://sec.okta.com/articles/2021/12/log4shell
https://blog.cloudflare.com/how-cloudflare-security-responded-to-log4j2-vulnerability/
Further information
https://www.ncsc.gov.uk/news/apache-log4j-vulnerability
https://github.com/NCSC-NL/log4shell/tree/main/software