[nSign] Vulnerability in Apache Log4j Library (CVE-2021-44228)

[nSign] Vulnerability in Apache Log4j Library (CVE-2021-44228)

Summary

On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j versions prior to 2.15.0 was disclosed:

  1. CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Products Investigation

Netrust has completed the investigation on our products and the following product is affected:
  1. nSign version <= 3.0.24
The interim vulnerability fix for Windows and Linux can be found below:

Workarounds

-Work in progress-


Note: A patch will be released to permanently address the vulnerability.

    • Related Articles

    • [Transaction Signing] Vulnerability in Apache Log4j Library (CVE-2021-44228)

      Summary On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j versions prior to 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP ...
    • [nSeal/SAM] Vulnerability in Apache Log4j Library (CVE-2021-44228)

      Summary On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j versions prior to 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP ...
    • nSign Desktop Upgrade Guide

      Step 1. Start up the installed instance of nSign Desktop. Step 2: Click on 'Help' and 'About' to check the current version of nSign Desktop. Step 3:  Take note of the Version number of nSign Desktop highlighted in red below. The version in this case ...
    • [nSign] Tomcat Upgrade Guide for Windows

      1 Download latest version of Apache Tomcat Select 32-bit/64-bit Windows Service Installer Transfer Installer into Windows Server Hosting Netrust Application 2. Tomcat Upgrade 2.1. Files and Configuration Backup Create a folder ‘<Netrust ...
    • nSign Desktop Troubleshooting Guide (STAGING)

      Login failed, unable to locate a digital identity. Upon encountering this error - 'Login failed, unable to locate a digital identity',  1. Download the following certificate files, Netrust Test CA2 and Netrust Test CA2-1 and save them somewhere ...