๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๊ฐœ๋ฐœ/etc

[Log4j2 ์ทจ์•ฝ์  ์ด์Šˆ] spring boot ๋‚ด์žฅ๋œ Log4j2 ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ฒ„์ „ ๋ณ€๊ฒฝํ•˜๊ธฐ (maven, gradle)

by ynzu๐Ÿค 2021. 12. 17.
๋ฐ˜์‘ํ˜•

์ง€๋‚œ์ฃผ ์ฃผ๋ง์— log4j2 ์ทจ์•ฝ์  ์ด์Šˆ๊ฐ€ ์žˆ์—ˆ๋‹ค.

๋‹คํ–‰ํžˆ ์šฐ๋ฆฌ ํ”„๋กœ์ ํŠธ์—์„  ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” log4j2-core๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์ง€ ์•Š์•˜์ง€๋งŒ log4j2-api, log4j-to-slf4์™€ ๊ฐ™์€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋„ ์ตœ์‹ ํ™”ํ•˜๊ณ ์ž ํ–ˆ๋‹ค.

Spring Boot ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์— ๋‚ด์žฅ๋œ log4j2๋ฅผ ์‚ฌ์šฉ ์ค‘์ด์˜€๊ณ , ๋จผ์ € Spring Boot์˜ ๋ฒ„์ „์„ ๊ฐ€์žฅ ์ตœ์‹  ๋ฒ„์ „์ธ 2.6.1๋กœ ๋ณ€๊ฒฝํ•˜์˜€๋‹ค.

ํ•˜์ง€๋งŒ 2.6.1 ๋ฒ„์ „์— ๋‚ด์žฅ๋œ log4j2์˜ ๋ฒ„์ „์€ 2.14.1์ด์˜€๊ณ .. ๋‚ด์žฅ๋œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ๋ฒ„์ „์„ ๋ณ€๊ฒฝํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ฐพ์•„ ํ•ด๊ฒฐํ•˜์˜€๋‹ค!

 

๋ฐฉ๋ฒ•1

2.17.0์ธ log4j-api, log4j-to-slf4j๋ฅผ ์„ ์–ธํ•ด์ฃผ๋ฉด spring boot์— ๋‚ด์žฅ๋œ log4j์˜ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ฒ„์ „์ด ๋ณ€๊ฒฝ๋œ๋‹ค.

  • gradle
implementation group: 'org.apache.logging.log4j', name: 'log4j-api', version: '2.17.0'
implementation group: 'org.apache.logging.log4j', name: 'log4j-to-slf4j', version: '2.17.0'

 

  • maven
<dependency>
	<groupId>org.apache.logging.log4j</groupId>
	<artifactId>log4j-api</artifactId>
	<version>2.17.0</version>
</dependency>

<dependency>
	<groupId>org.apache.logging.log4j</groupId>
	<artifactId>log4j-to-slf4j</artifactId>
	<version>2.17.0</version>
</dependency>

 

 

 ๋ฐฉ๋ฒ•2

  • gradle
// ์ข…์†์„ฑ ๊ด€๋ฆฌ ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์‚ฌ์šฉ์ค‘์ด๋ผ๋ฉด 
ext['log4j2.version'] = '2.17.0'

//์ข…์†์„ฑ ๊ด€๋ฆฌ ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ์•„๋‹Œ gradle ํ”Œ๋žซํผ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ
implementation(platform("org.apache.logging.log4j:log4j-bom:2.17.0"))

 

  • maven
<properties>
	<log4j2.version>2.17.0</log4j2.version>
</properties>

 

์šฐ๋ฆฐ ๋ฐฉ๋ฒ• 2๋กœ ์„ค์ •ํ–ˆ๋‹ค. ์ฒ˜์Œ์—” ๋ฐฉ๋ฒ• 1๋กœ ํ–ˆ์ง€๋งŒ ํ•œ๋ฒˆ์— ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ• 2์„ ๋’ค๋Šฆ๊ฒŒ ์•Œ์•„์ฑ„๊ณ ..!
spring boot์˜ ๋ฒ„์ „์ด ๋นจ๋ฆฌ ์—…๋ฐ์ดํŠธ ๋˜๊ธธ..
log4j2๊ฐ€ ์•„๋‹ˆ๋”๋ผ๋„ ๋‚ด์žฅ๋œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ๋ฒ„์ „์„ ๋ณ€๊ฒฝํ•  ์ผ์ด ์ƒ๊ธฐ๋ฉด ์œ„ ๋ฐฉ๋ฒ•๋Œ€๋กœ ํ•˜๋ฉด ๋œ๋‹ค.
(spring boot์— ๋‚ด์žฅ๋œ tomcat ๋ฒ„์ „๋„ ์ด ๋ฐฉ๋ฒ•๋Œ€๋กœ ๋ณ€๊ฒฝํ•˜์˜€์—ˆ๋‹ค)

 

๊ฒฐ๊ณผ

 

JAVA 8์˜ ๊ฒฝ์šฐ ์—…๋ฐ์ดํŠธ๋œ ๊ฐ€์žฅ ์ตœ์‹  ๋ฒ„์ „์€ 2.17.0์ž…๋‹ˆ๋‹ค! (CVE-2021-45046)

 

์ฐธ๊ณ ์‚ฌ์ดํŠธ

apache ๋ณด์•ˆ์—…๋ฐ์ดํŠธ ํ˜„ํ™ฉ : https://logging.apache.org/log4j/2.x/security.html
์ทจ์•ฝ์  ์ •๋ณด :
https://nvd.nist.gov/vuln/detail/CVE-2021-45105
์‹ ๊ทœ๋ฒ„์ „ ๋‹ค์šด๋กœ๋“œ :
https://logging.apache.org/log4j/2.x/download.html



 

728x90
๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€