Ubiquiti UniFi: remote code execution via bundled log4j A vulnerability has been discovered in unifi where bundled log4j can facilitate a remote code execution unifi 2023-10-26 2023-10-26 828853 remote 6.5.55 6.5.55

Ubiquiti UniFi is a Management Controller for Ubiquiti Networks UniFi APs.

A bundled version of log4j could facilitate remote code execution. Please review the CVE identifier referenced below for details.

An attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code.

There is no known workaround at this time.

All Ubiquity UniFi users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-wireless/unifi-6.5.55"
CVE-2021-4104 CVE-2021-45046 graaff graaff