FAQ  •  Register  •  Login

logj4 Mitigation necessary? In the pipeline?

<<

cjohnmurphy

Serviio newbie

Posts: 2

Joined: Mon Dec 13, 2021 1:02 am

Post Mon Dec 13, 2021 1:07 am

logj4 Mitigation necessary? In the pipeline?

Serviio seems to use an older version of log4j. What is the plan to mitigate the ongoing attack vector in the log4j product?
<<

atc98092

User avatar

DLNA master

Posts: 5213

Joined: Fri Aug 17, 2012 10:22 pm

Location: Washington (the state)

Post Mon Dec 13, 2021 1:22 am

Re: logj4 Mitigation necessary? In the pipeline?

Serviio uses BItbucket for tracking bugs and enhancements. I suggest posting this information there, so the developer can track and provide feedback for the issue. I searched for any entries for log4j and found none.

https://bitbucket.org/xnejp03/serviio/issues
Dan

LG NANO85 4K TV, Samsung JU7100 4K TV, Sony BDP-S3500, Sharp 4K Roku TV, Insignia Roku TV, Roku Ultra, Premiere and Stick, Nvidia Shield, Yamaha RX-V583 AVR.
Primary server: Intel i5-6400, 16 gig ram, Windows 10 Pro, 22 TB hard drive space | Test server Windows 10 Pro, AMD Phenom II X4 965, 8 gig ram

HOWTO: Enable debug logging HOWTO: Identify media file contents
<<

zip

User avatar

Serviio developer / Site Admin

Posts: 17212

Joined: Sat Oct 24, 2009 12:24 pm

Location: London, UK

Post Mon Dec 13, 2021 5:46 pm

Re: logj4 Mitigation necessary? In the pipeline?

Just released 2.2.1 which has the latest (fixed) version of log4j
<<

jeiz

Serviio newbie

Posts: 1

Joined: Fri Dec 17, 2021 9:21 am

Post Fri Dec 17, 2021 9:26 am

Re: logj4 Mitigation necessary? In the pipeline?

zip wrote:Just released 2.2.1 which has the latest (fixed) version of log4j


2.2.1 appears to contain log4j 2.15.0 and regrettably that was an incomplete fix, so Apache has now released log4j 2.16.0 (hopefully the last for a while!).

Edit: Ugh ... Apache has released log4j 2.17.0 (2.16.0 still vulnerable to DoS).

Edit: ... and Apache has released log4j 2.17.1 (2.17.0 still vulnerable to RCE via a different attack)

Is an updated version of serviio in the pipeline?
<<

burgergold

Serviio newbie

Posts: 2

Joined: Sun Jan 09, 2022 2:24 pm

Post Sun Jan 09, 2022 2:39 pm

Re: logj4 Mitigation necessary? In the pipeline?

same, please release a new version with log4j 2.17.1
<<

bbqf

Serviio newbie

Posts: 2

Joined: Wed Jun 08, 2022 3:19 pm

Post Wed Jun 08, 2022 3:22 pm

Re: logj4 Mitigation necessary? In the pipeline?

+1 on the topic!
It's been a while since the log4j issue has been found and fixed, it would be great to have a serviio with a fixed version of it!
<<

atc98092

User avatar

DLNA master

Posts: 5213

Joined: Fri Aug 17, 2012 10:22 pm

Location: Washington (the state)

Post Wed Jun 08, 2022 6:09 pm

Re: logj4 Mitigation necessary? In the pipeline?

Last I was advised by Zip, the next version of Serviio should reach beta testing sometime this summer. I have no clue what is in the next version, but I would expect he will ensure log4j is addressed.
Dan

LG NANO85 4K TV, Samsung JU7100 4K TV, Sony BDP-S3500, Sharp 4K Roku TV, Insignia Roku TV, Roku Ultra, Premiere and Stick, Nvidia Shield, Yamaha RX-V583 AVR.
Primary server: Intel i5-6400, 16 gig ram, Windows 10 Pro, 22 TB hard drive space | Test server Windows 10 Pro, AMD Phenom II X4 965, 8 gig ram

HOWTO: Enable debug logging HOWTO: Identify media file contents

Return to Serviio Support & Help

Who is online

Users browsing this forum: Majestic-12 [Bot] and 38 guests

cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by ST Software for PTF.