Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
1234...

Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
66 Reply
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 08:58:43

Dear @ggeoffreyyy,

 

ggeoffreyyy wrote

When can we expects a full release?

Something as critical as this can't be put out as a "beta." If used in production we need these fixed and we can't push through a change for a beta release.

 

The official release is on the way, will be published soon. Please wait patiently.

 

Actually, the Beta firmware has been tested and confirmed to be effective, it just hasn't gone through an internal review process for official release (which takes a long time). If you are looking for an urgent solution, the Beta firmware can also be a reliable option.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#22
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 09:02:05

Dear @Rob_ARN,

 

Rob_ARN wrote

I am running an OC200 old version because I need to support eap245 v1 devices.

Will there be a fix for this as well?

 

The beta firmware for OC200 1.2.4 has just been provided in this solution.

 

The official firmware will be released soon.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  1  
  1  
#23
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 16:37:43 - last edited 2021-12-15 22:03:01

Installed the update successfully on Ubuntu over SSH, sad that the controller won't start anymore. Reboot of my system didn't help :(

 

 

Edit: Uninstalled curl which also uninstalled omadac. Did a fresh install of the 4.4.6 deb-file using 'dpkg -i' and now it's back up. Lost all my settings though but luckily I took some back-ups out of the autobackup-folder before doing this. Now it's all working again :)

  0  
  0  
#24
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 17:20:27

@Fae 

 

It seems we will need another update for log4j version to 2.16.0 (CVE-2021-45046).

  2  
  2  
#25
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 18:42:06

@Fae For the OC200 and OC300, two questions:

  1. Is there a workaround OTHER than the beta patch?  (the numerous failures reported here do not inspire confidence)
  2. Is there any idea what "soon" might be for non-beta firmware?
  3. Can the access points (and for my home installation: router and switches) continue to run if the controller is taken offline until a non-beta fix is supplied?
  0  
  0  
#26
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 19:47:22

@Fae 

 

Hi,

 

Be aware that Omada SDN 4.4.6 BETA (Omada_SDN_Controller_v4.4.6_beta_linux_x64_20211213180823) embeds log4j 2.15 which is known to still be vulnerable 

/opt/tplink/EAPController/lib/log4j-slf4j-impl-2.15.0.jar
/opt/tplink/EAPController/lib/log4j-api-2.15.0.jar
/opt/tplink/EAPController/lib/log4j-core-2.15.0.jar

 

Log4j 2.15 addresses part of CVE-2021-44228 but is still vulnerable to derivatives ; these are referred in CVE-2021-45046

https://logging.apache.org/log4j/2.x/security.html

 

TPLink, please do not release the "fixed" version unless you upgraded log4j to 2.16.0 and please release a beta2 version.

 

Regards.

  1  
  1  
#27
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-15 19:53:14

@johnsnow88 

 

Unifi was super fast this time to, I have alredy upgraded a bunch of unifi controllers. with CVE-2021-45046 patch, @Fae when can we eksept this update from TP-LINK?

Lets hope this is end of Log4j patch

 

 

  0  
  0  
#28
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-16 03:10:50

Dear @johnsnow88, @JustAnotherDave@caramb@shberge,

 

shberge wrote

with CVE-2021-45046 patch, @Fae when can we except this update from TP-LINK?

Lets hope this is end of Log4j patch


The coming official firmware will update log4j version to 2.16.0 (CVE-2021-45046).

 

FYI, the final fix for Omada SDN Controller_Windows/Linux is expected to be released this week.

And Omada SDN Controller OC200/OC300 may be released earlier next week (two or three days later).

(The test projects of Hardware Controller is a bit more than the Software Controller, so it will take more time.)

Note: the final release date is subject to the actual release of the official firmware.

 

 

The official firmware release is already being expedited, but it still needs some time to conduct the full tests first, hope you understand.

 

Thank you for your great patience and understanding!

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  2  
  2  
#29
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-16 03:18:27

Dear @JustAnotherDave,

 

JustAnotherDave wrote

For the OC200 and OC300, two questions:

  1. Is there a workaround OTHER than the beta patch?  (the numerous failures reported here do not inspire confidence)
  2. Is there any idea what "soon" might be for non-beta firmware?
  3. Can the access points (and for my home installation: router and switches) continue to run if the controller is taken offline until a non-beta fix is supplied?

 

The official firmware will be released soon (I assume earlier next week). Please wait patiently.

 

If the controller is offline(unplugged), the Omada devices can still work with basic functions, but some advanced features will not take effect.

For more details, please kindly check the article below (it applied to all Omada Devices including the router and switch).

 

Will the Configuration Still Work with EAPs When the Omada Controller Goes Offline?

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#30
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-16 05:00:10

FWIW, I have Omada_Controller_V5.0.27_Windows installed now and it's MUCH faster/more responsive than previous releases. Pages seem to load twice as fast as they did even under 5.0.15. Not sure what else they updated/fixed in the release but something created a nice performance boost. Hope it sticks!

  0  
  0  
#33
Options