# Log4j vulnerability

**URL:** <https://community.openhab.org/t/log4j-vulnerability/129863>\
**Category:** Development\
**Created:** [December 10, 2021, 3:04pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863 "2021-12-10T15:04:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 3:04pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/1 "2021-12-10T15:04:31Z")

</div>

Hi everyone,

has anyone looked into CVE-2021-44228? I believe openHAB could be affected by this aswell so this should be addressed before the next release.

@Kai please keep this in mind when planning the next release.

---

<div class="post-metadata">

**Author:** ![Kai](https://community.openhab.org/user_avatar/community.openhab.org/kai/32/116281_2.png) [@Kai](https://community.openhab.org/u/Kai)\
**Post date:** [December 10, 2021, 3:42pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/2 "2021-12-10T15:42:04Z")

</div>

Hi @Flole,

That’s a good point, this CVE makes quite some high waves today.  
We should indeed check how we can address it for 3.2.  
Unfortunately, we are using Karaf, which in turn uses OPS4J Pax Logging, which builds on top of log4j (currently only version 2.0.10) - so we have a nasty dependency chain here, which isn’t easy to resolve.

@wborn Would you see any way how we could possibly update to 2.15.0 without having to wait for the other projects to do new releases?

If we can’t find a good way to upgrade, we should be able to mitigate the vulnerability - according to [the advisory](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q), it is possible to set the system parameter `log4j2.formatMsgNoLookups` to `true` for this.

---

<div class="post-metadata">

**Author:** ![Kai](https://community.openhab.org/user_avatar/community.openhab.org/kai/32/116281_2.png) [@Kai](https://community.openhab.org/u/Kai)\
**Post date:** [December 10, 2021, 4:27pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/3 "2021-12-10T16:27:01Z")

</div>

FTR: PAX Logging has already been fixed with a new release: [[CVE-2021-44228] Upgrade to log4j2 2.15.0 · Issue #414 · ops4j/org.ops4j.pax.logging · GitHub](https://github.com/ops4j/org.ops4j.pax.logging/issues/414#issuecomment-991109133)

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 4:36pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/4 "2021-12-10T16:36:26Z")

</div>

That means Karaf is the next link in the chain which needs to update, right? I think the issue for that over at karafs issue tracker is [[KARAF-7262] Upgrade to Pax Logging 2.0.11 - ASF Jira](https://issues.apache.org/jira/browse/KARAF-7262), not sure how they managed to create that issue before 2.0.11 was even released… It’s targeted for Karaf 4.3.4, not sure which version we are using but maybe it’s a good idea to comment on that issue to stress that this is important as it fixes that CVE.

I think instead of updating to an untested Karaf version it might be better to use the workaround for now and then for the next release include the fix. Updating Karaf seems to be a bigger change that should be tested with a Milestone and not just thrown into a release kinda last minute IMO.

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 4:41pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/5 "2021-12-10T16:41:17Z")

</div>

Is there something, that we (users) can do with the actual 3.1 release?  
Is the openhab-cloudservice affected ?

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 4:49pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/6 "2021-12-10T16:49:14Z")

</div>

That is a great question. I would assume (and this is only an assumption!) that you can add

```auto
-Dlog4j2.formatMsgNoLookups=true

```

to the `EXTRA_JAVA_OPTS` in `/etc/default/openhab`. If you are still on openHAB 2.x then that file would be `/etc/default/openhab2`.

For example:

```auto
EXTRA_JAVA_OPTS="-Dlog4j2.formatMsgNoLookups=true" 

```

If this is confirmed as a fix this should be posted as an anouncement. The cloud service is based on node.js IIRC, so it shouldn’t be affected. OHs Demo Instance could be affected though.

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 4:52pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/7 "2021-12-10T16:52:44Z")

</div>

> [@Flole](#):
>
> `EXTRA_JAVA_OPTS`

in which file you mean to add the option?

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 4:54pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/8 "2021-12-10T16:54:16Z")

</div>

Are you on WIndows or Linux? For Linux I stated the file for OH 3.x and 2.x, for Windows I would have to double-check. I’d guess it’s in the start.bat and start-debug.bat (assuming those files still exist).

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 4:54pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/9 "2021-12-10T16:54:41Z")

</div>

Windows …running as a service with the service-wrapper…

openHAB-wrapper.conf ?  
or setenv.bat ?..there is already a EXTRA\_JAVA\_OPTS section

---

<div class="post-metadata">

**Author:** ![Kai](https://community.openhab.org/user_avatar/community.openhab.org/kai/32/116281_2.png) [@Kai](https://community.openhab.org/u/Kai)\
**Post date:** [December 10, 2021, 4:57pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/10 "2021-12-10T16:57:02Z")

</div>

@Flole Right, I just found the very same Karaf issue and commented on it. We are currently on 4.3.3, so upgrading to 4.3.4 would be a logical step. I assume that they are working on that release right now.

> Is the openhab-cloudservice affected ?

@RalphSester No, this is using node.js, no Java.

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 4:59pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/11 "2021-12-10T16:59:21Z")

</div>

For Windows it should be (again, just guessing here) `openHAB-wrapper.conf`, and the syntax there is a little different:

```auto
wrapper.java.additional.XX=-Dlog4j2.formatMsgNoLookups=true

```

where XX is the next available number in the sequence of lines. So if you have

```auto
# Java Parameters
wrapper.java.additional.1=-Dkaraf.home="%KARAF_HOME%"
wrapper.java.additional.2=-Dkaraf.base="%KARAF_BASE%"
wrapper.java.additional.3=-Dkaraf.data="%KARAF_DATA%"
wrapper.java.additional.4=-Dkaraf.etc="%KARAF_ETC%"
wrapper.java.additional.5=-Dcom.sun.management.jmxremote
wrapper.java.additional.6=-Dkaraf.startLocalConsole=false
wrapper.java.additional.7=-Dkaraf.startRemoteShell=true
wrapper.java.additional.8=-Dopenhab.home="%OPENHAB_HOME%"
wrapper.java.additional.9=-Dopenhab.conf="%OPENHAB_HOME%\conf"
wrapper.java.additional.10=-Dopenhab.runtime="%OPENHAB_HOME%\runtime"
wrapper.java.additional.11=-Dopenhab.userdata="%OPENHAB_HOME%\userdata"
wrapper.java.additional.12=-Dopenhab.logdir="%OPENHAB_USERDATA%\logs"
wrapper.java.additional.13=-Dfelix.cm.dir="%OPENHAB_HOME%\userdata\config"
wrapper.java.additional.14=-Dorg.osgi.service.http.port=8080
wrapper.java.additional.15=-Dorg.osgi.service.http.port.secure=8443
wrapper.java.additional.16=-Djava.util.logging.config.file="%KARAF_ETC%\java.util.logging.properties"
wrapper.java.additional.17=-Dkaraf.logs="%OPENHAB_LOGDIR%"
wrapper.java.additional.18=-Dfile.encoding=UTF-8

```

as mentioned in the [documentation](https://www.openhab.org/docs/installation/windows.html#set-up-openhab-to-run-as-a-windows-service) you should add

```auto
wrapper.java.additional.19=-Dlog4j2.formatMsgNoLookups=true

```

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 4:59pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/12 "2021-12-10T16:59:56Z")

</div>

ok - thank you…i will test it.

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 5:05pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/13 "2021-12-10T17:05:14Z")

</div>

I have set the parameter in the openHAB-wrapper.conf and restarted the service.

Everything seems fine again.  
Is there a way, which i can test, if the parameter is active in the running instance?

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 5:07pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/14 "2021-12-10T17:07:57Z")

</div>

I would guess it can be checked on the karaf console using

```auto
system:property log4j2.formatMsgNoLookups

```

which should say “true” and not “null”.

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 5:10pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/15 "2021-12-10T17:10:12Z")

</div>

> [@Flole](#):
>
> `system:property org.log4j2.formatMsgNoLookups`

its “null”

---

<div class="post-metadata">

**Author:** ![Flole](https://community.openhab.org/letter_avatar_proxy/v4/letter/f/bcef8e/32.png) [@Flole](https://community.openhab.org/u/Flole)\
**Post date:** [December 10, 2021, 5:12pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/16 "2021-12-10T17:12:00Z")

</div>

Sorry that command was wrong, that “org.” shouldn’t be there. I corrected my post.

---

<div class="post-metadata">

**Author:** ![RalphSester](https://community.openhab.org/user_avatar/community.openhab.org/ralphsester/32/28533_2.png) [@RalphSester](https://community.openhab.org/u/RalphSester)\
**Post date:** [December 10, 2021, 5:13pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/17 "2021-12-10T17:13:07Z")

</div>

ok…now it’s “true” 😉

so could that now be called a “solution”?  
What side effects can the parameter cause in OpenHAB?  
Can I test this somehow?

---

<div class="post-metadata">

**Author:** ![Kai](https://community.openhab.org/user_avatar/community.openhab.org/kai/32/116281_2.png) [@Kai](https://community.openhab.org/u/Kai)\
**Post date:** [December 10, 2021, 5:17pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/18 "2021-12-10T17:17:33Z")

</div>

Cool, thanks for testing, guys.  
@Flole Could you do a PR against openhab-distro with that? We would then have the snapshots already covered.  
I’m also thinking about doing a 3.1.1 patch release with this, if I can get that going.  
For 3.2, I’d then hope for Karaf 4.3.4 becoming available on time.

---

<div class="post-metadata">

**Author:** ![rlkoshak](https://community.openhab.org/user_avatar/community.openhab.org/rlkoshak/32/75251_2.png) [@rlkoshak](https://community.openhab.org/u/rlkoshak)\
**Post date:** [December 10, 2021, 5:18pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/19 "2021-12-10T17:18:24Z")

</div>

Don’t take this as speaking against anything discussed here regarding fixes and mitigations and such.

But my reading of this is that it’s only an issue if log4j2 is configured to use a JNDI service. My reading of log4j2.xml is that the OH config, by default, does not use and JNDI in the configs. So the actual exposure to most of our users to this CVE is limited to those who have modified log4j2.xml to use JNDI features.

Given that, in any announcement made and whatnot we need to be careful not to scare everyone about their system having already been hacked or something like that. For those who have modified log4j2.xml it’s prudent to add the environment variable until the fix rolls out. For the rest, it’s probably a good idea but not critical because they haven’t actually had any exposure to it to date.

Of course this all goes out the window if OPS4J Pax. Logging or Karaf do some JNDI stuff in code or outside of the exposed log4j2.xml config.

---

<div class="post-metadata">

**Author:** ![Kai](https://community.openhab.org/user_avatar/community.openhab.org/kai/32/116281_2.png) [@Kai](https://community.openhab.org/u/Kai)\
**Post date:** [December 10, 2021, 5:23pm UTC](https://community.openhab.org/t/log4j-vulnerability/129863/20 "2021-12-10T17:23:04Z")

</div>

Thanks for joining in @rlkoshak! You raise a good point. I am actually not sure how the JNDI is activated and used in this context. So I guess you’re right and it makes sense to dig a bit deeper to really understand the issue first in detail.

> My reading of log4j2.xml is that the OH config, by default, does not use and JNDI in the configs.

Could you elaborate on this, please? Does JNDI have to be activated in the xml to be a problem?

[Next page](https://community.openhab.org/t/log4j-vulnerability/129863.md?page=2)
