Showing posts with label Spring. Show all posts
Showing posts with label Spring. Show all posts

December 14, 2021

Fixing the Log4j2 vulnerability in spring boot application

 Hi all,

Software Industry was in a shock with the log4j2 zero day exploit.

Exploited area

The Apache Log4j2 version ( >=2.0 to <=2.14.1 ) is exploitable due to an attacker controlled LDAP and  JNDI endpoints.

Appendix

LDAP (Light Weight Directory Protocol) is an industry standard protocol to access directory services.

JNDI (Java Naming and Directory Interface) is a Java API for a directory service that allows Java software clients to discover and look up data and resources via a name.

Find more information about the vulnerability from NVD website link.

https://nvd.nist.gov/vuln/detail/CVE-2021-44228

NVD (National Vulnerability Database) is maintained by National Institute of Standards and Technology (NIST),  An official part of United States of America (USA) government's Department of Commerce.

Fix the vulnerability

  • Even in the latest spring boot package uses the vulnerable 2.14.1 log4j2 version.
  • So, we need to explicitly add the specific version in the properties as below
  • In pom.xml file, creating <properties> tag if not exists and add the attribute log4j2.version with version 2.16.0 (latest)

<properties>

    <log4j2.version>2.16.0</log4j2.version>

</properties>

  • To check the version applied to the project, run the following command
mvn dependency:tree | grep "log4j"
  • The result should look like below
[INFO] |  |  |  +- org.apache.logging.log4j:log4j-to-slf4j:jar:2.16.0:compile
[INFO] |  |  |  |  \- org.apache.logging.log4j:log4j-api:jar:2.16.0:compile

  • The similar type of vulnerability fixes available for other project builds.


Hope you will find the above information useful and fix the issue immediately to keep the servers safe from attacks.

Send your valuable feedback and comments to psrdotcom@gmail.com

 

December 09, 2014

Manually Adding Dependency in Spring MicroSoft SQLServer JDBC Driver

Hi Friends,

Today, I’ve spent more than 40 minutes in understanding the process and setting up the SQLServer JDBC Driver in Spring manually

Pre-requisites

Maven (Download from http://maven.apache.org/download.cgi and add the maven path to environment variables)

Procedure

  1. Download the latest Microsoft JDBC driver for SQL Server from the following official link http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=11774
  2. I’ve selected sqljdbc jar version 4.0
  3. Navigate to the extracted folder where .jar files available in command prompt
  4. Execute the following command
  5. cmd> mvn install:install-file -DgroupId=com.microsoft.sqlserver.jdbc -DartifactId=sqljdbc -Dversion=4.0 -Dpackaging=jar -Dfile="sqljdbc4.jar"
     
  6. Now you should be able to see the downloading and moving the corresponding .jar and .pom files. Then a message “BUILD SUCCESS” will appear in command prompt.
  7. Add the following dependency to your pom.xml
<!-- Database -->
<dependency>
<groupId>com.microsoft.sqlserver.jdbc</groupId>
<agtifactId>sqljdbc</agtifactId>
<version>4.0</version>
</dependency>

    Now you run the project and enjoy the usage of SQLServer Database with Spring.

    Please send your feedback and comments to psrdotcom@gmail.com

    Blogger Labels: Dependency,MicroSoft,SQLServer,JDBC,Driver,Friends,Procedure,Download,Server,version,Navigate,folder,Execute,DgroupId,DartifactId,Dversion,Dfile,message,BUILD,Database,usage,feedback,sqljdbc,groupId,artifactId

    Featured Post

    Java Introdcution

    Please send your review and feedback to psrdotcom@gmail.com