{"id":19386,"date":"2021-12-14T12:33:50","date_gmt":"2021-12-14T20:33:50","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=19386"},"modified":"2024-01-23T22:23:53","modified_gmt":"2024-01-24T06:23:53","slug":"private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/","title":{"rendered":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On\u00a0December 9, 2021, a\u00a0zero-day vulnerability\u00a0was\u00a0disclosed\u00a0in the open-source Apache library in one of its Java-logging frameworks\u00a0\u2013\u00a0Log4j\u00a02, with the vulnerability being named\u00a0\u201cLog4Shell\u201d.\u00a0Cybersecurity agencies around the world are correctly calling this a massive, critical-level\u00a0threat,\u00a0with\u00a0tech\u00a0experts\u00a0sounding the alarm\u00a0and\u00a0saying\u00a0that\u00a0the Log4Shell exploit is,\u00a0\u201c<a href=\"https:\/\/www.theguardian.com\/technology\/2021\/dec\/10\/software-flaw-most-critical-vulnerability-log-4-shell\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the single biggest, most critical vulnerability of the last decade.<\/a>\u201d\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since the threat was\u00a0disclosed,\u00a0our\u00a0engineers\u00a0have been working\u00a0around-the-clock\u00a0to\u00a0come up with\u00a0a patch\u00a0that can not only protect\u00a0our\u00a0users from exploits in our system but can\u00a0also\u00a0help\u00a0protect\u00a0PIA\u2019s VPN\u00a0users from the Log4j 2 vulnerability altogether. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>We\u2019ve issued an update to our VPN infrastructure that now protects all PIA users against most Log4Shell exploits while they\u2019re connected to the VPN (but, as we\u2019ll note in this article, it\u2019s not a foolproof solution). <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s\u00a0what we did:\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>We\u2019ve\u00a0Blocked\u00a0Traffic to\u00a0the Lightweight Directory Access Protocol (LDAP)<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The\u00a0Log4Shell\u00a0exploit has been found to\u00a0primarily\u00a0use\u00a0certain ports of the\u00a0networking protocol LDAP.\u00a0Considering that we can simply block\u00a0LDAP traffic from going through our VPN,\u00a0we\u2019ve\u00a0decided that not only is this a practical solution to overcome\u00a0the main\u00a0Log4Shell exploit, but that\u00a0it\u2019s\u00a0our duty as a network-based\u00a0security service to do so.\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By blocking LDAP traffic, an\u00a0attacker\u00a0can no\u00a0longer\u00a0force your device to\u00a0connect\u00a0to a suspicious LDAP\u00a0server and load the\u00a0malicious\u00a0code\u00a0used in\u00a0the\u00a0exploit.\u00a0To achieve this,\u00a0we\u2019ve\u00a0implemented firewalls across\u00a0all of\u00a0our VPN servers that block certain\u00a0LDAP ports known to be used in the attacks.\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This effectively blocks\u00a0most\u00a0Log4Shell\u00a0exploits\u00a0at\u00a0the network level,\u00a0ensuring that no malicious\u00a0code\u00a0can\u00a0be sent via\u00a0these\u00a0attack vectors.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a foolproof, long-term solution, and you should focus on upgrading any Java application that you are currently using on your device\u00a0for complete Log4Shell protection. For a full list of vulnerable applications, go <a href=\"https:\/\/github.com\/NCSC-NL\/log4shell\/blob\/main\/software\/README.md\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">here<\/a>.\u00a0<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color wp-block-paragraph\"><span style=\"text-decoration: underline;\"><strong>In short: Simply connecting to PIA\u2019s VPN\u00a0now\u00a0protects against the main way hackers exploit\u00a0the Log4j\/Log4Shell vulnerability.<\/strong><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>We\u2019ve\u00a0Also\u00a0Identified &amp;\u00a0Taken Extra Security Measures\u00a0to Guarantee Internal\u00a0Safety<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While it needs to be noted that at no point is\/was any user data threatened or compromised,\u00a0we\u2019ve\u00a0taken extra security measures to make sure our\u00a0internal\u00a0systems stay rock solid.\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Specifically, we\u2019ve:\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\" style=\"font-size:15px\"><li>Updated all affected infrastructure to their latest OS versions and applied all security patches.\u00a0<\/li><li>Updated all affected internal tools to their latest versions, including fixes for the Log4j vulnerability.\u00a0<\/li><li>Audited and patched all affected docker images, including fixes for the Log4j vulnerability.\u00a0<\/li><li>Patched all server fleets against the Log4j\u00a0vulnerability,\u00a0including releasing\u00a0the LDAP fix\u00a0by\u00a0blocking a series of ports\u00a0most commonly used\u00a0by the LDAP protocol.\u00a0<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What Is Log4j 2 &amp; Log4Shell?\u00a0<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Apache Log4j 2 is a Java-logging package that creates and saves log reports, like when you send an error report to a developer to\u00a0help them debug\u00a0a misbehaving application. This is a typical function of the\u00a0Java-logging\u00a0code, and it has no privacy-based risks associated with it.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the Log4Shell vulnerability allows an attacker to create a log\u00a0that\u2019s\u00a0saved locally on your device while\u00a0being able to\u00a0connect to an\u00a0additional\u00a0server\u00a0to get\u00a0additional\u00a0log content. By doing so,\u00a0the attacker can retrieve logging data from your server, upload malware onto that server, and execute their\u00a0malware locally on your device.\u00a0<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"957\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/image-2-1024x957.png\" alt=\"\" class=\"wp-image-19415\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/image-2-1024x957.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/image-2-300x281.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/image-2-768x718.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/image-2.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, Log4j 2 is extremely well integrated across the entirety of the web\u2019s infrastructure, posing potentially catastrophic risks for\u00a0virtually all\u00a0internet-connected services.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a successful exploit has already been used against the popular game Minecraft, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/minecraft-rushes-out-patch-for-critical-log4j-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">as the simple sending of a chat message allowed the attacker to gain access to\u00a0Minecraft\u2019s\u00a0servers<\/a>.\u00a0While this\u00a0vulnerability\u00a0has\u00a0since\u00a0been patched\u00a0within\u00a0Minecraft,\u00a0there\u2019s\u00a0no way to tell what software has\u00a0already\u00a0been compromised and what software\u00a0still\u00a0remains\u00a0vulnerable (unless a patch has already been issued and communicated).\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, Log4Shell attacks\u00a0don\u2019t\u00a0need the victim to click any link or take any action \u2013 they can be executed easily and quickly, and\u00a0virtually every type of malware (from spyware to ransomware) can be loaded onto a user\u2019s system.\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, as noted,\u00a0simply\u00a0connecting to PIA\u2019s VPN will\u00a0now\u00a0help protect against\u00a0this\u00a0vulnerability.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to Stay\u00a0Fully\u00a0Protected Against Log4Shell<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Critically, while PIA\u2019s VPN\u00a0now\u00a0offers\u00a0network-based protection\u00a0against the Log4j exploit\u00a0by blocking common ports associated with\u00a0the vulnerability, if your software\u00a0or system\u00a0has not been\u00a0adequately patched, you\u00a0may\u00a0still be vulnerable.\u00a0Check regularly that your\u00a0system is updated and that\u00a0you\u00a0only use applications that have offered\u00a0specific Log4Shell-protection\u00a0updates.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to\u00a0ensure full\u00a0protection\u00a0against Log4Shell, you need to:\u00a0<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"font-size:15px\"><li><strong>Always connect to the internet using PIA\u2019s VPN.\u00a0If\u00a0you\u2019re\u00a0not yet using PIA\u2019s VPN, <a href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online\">you can get it here<\/a>.\u00a0<\/strong><\/li><\/ol>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\" style=\"font-size:15px\"><li><strong>Update\u00a0all of\u00a0your apps and software and regularly check for critical security updates. Many applications\u00a0and software services\u00a0will be issuing\u00a0Log4j 2\u00a0security fixes in the\u00a0very near\u00a0future.\u00a0<\/strong><\/li><\/ol>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\" style=\"font-size:15px\"><li><strong>Update your router\u00a0or\u00a0firewall\u2019s\u00a0settings to block traffic to ports\u00a0associated with Log4Shell, like RMI \u2013 1099 and LDAP \u2013 389, 636, 1389, 3268, and 3269.\u00a0We\u2019ve\u00a0blocked these in the VPN, but as an extra security measure, you should block these via your own\u00a0firewall.\u00a0<\/strong><\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Again, it needs to be noted that no PIA user information or data has been compromised. And\u00a0more importantly,\u00a0given our engineering team\u2019s quick response and mitigation efforts, we\u2019re\u00a0giving all\u00a0PIA VPN users a way to help stay protected against a zero-day exploit that the tech journal Wired has said,\u00a0\u201c<a href=\"https:\/\/www.wired.com\/story\/log4j-log4shell\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">will continue to wreak havoc across the internet for years to come.<\/a>\u201d\u00a0\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On\u00a0December 9, 2021, a\u00a0zero-day vulnerability\u00a0was\u00a0disclosed\u00a0in the open-source Apache library in one of its Java-logging frameworks\u00a0\u2013\u00a0Log4j\u00a02, with the vulnerability being named\u00a0\u201cLog4Shell\u201d.\u00a0Cybersecurity agencies around the world are correctly calling this a massive, critical-level\u00a0threat,\u00a0with\u00a0tech\u00a0experts\u00a0sounding the alarm\u00a0and\u00a0saying\u00a0that\u00a0the Log4Shell exploit is,\u00a0\u201cthe single biggest, most critical vulnerability of the last decade.\u201d\u00a0 Since the threat was\u00a0disclosed,\u00a0our\u00a0engineers\u00a0have been working\u00a0around-the-clock\u00a0to\u00a0come up with\u00a0a patch\u00a0that can &hellip; <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit&#8221;<\/span><\/a><\/p>\n","protected":false},"author":42,"featured_media":19416,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":false,"_modified_date":"","footnotes":""},"categories":[742,1,1937],"tags":[],"class_list":["post-19386","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcements","category-news","category-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit<\/title>\n<meta name=\"description\" content=\"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit\" \/>\n<meta property=\"og:description\" content=\"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-14T20:33:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-24T06:23:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Private Internet Access\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Private Internet Access\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\"},\"author\":{\"name\":\"Private Internet Access\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/bcf9eb65ae78fade9ba42096f055fb58\"},\"headline\":\"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit\",\"datePublished\":\"2021-12-14T20:33:50+00:00\",\"dateModified\":\"2024-01-24T06:23:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\"},\"wordCount\":1214,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg\",\"articleSection\":[\"Announcements\",\"General Privacy News\",\"VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\",\"name\":\"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg\",\"datePublished\":\"2021-12-14T20:33:50+00:00\",\"dateModified\":\"2024-01-24T06:23:53+00:00\",\"description\":\"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg\",\"width\":1920,\"height\":1280},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/bcf9eb65ae78fade9ba42096f055fb58\",\"name\":\"Private Internet Access\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f54349bf070d9a32816df7d40c3311a6a4cbfd4c70a3da4e9e678c43b509d02e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f54349bf070d9a32816df7d40c3311a6a4cbfd4c70a3da4e9e678c43b509d02e?s=96&d=mm&r=g\",\"caption\":\"Private Internet Access\"},\"sameAs\":[\"https:\/\/www.privateinternetaccess.com\"],\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/private-internet-access-research-team\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit","description":"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/","og_locale":"en_US","og_type":"article","og_title":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit","og_description":"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2021-12-14T20:33:50+00:00","article_modified_time":"2024-01-24T06:23:53+00:00","og_image":[{"width":1920,"height":1280,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg","type":"image\/jpeg"}],"author":"Private Internet Access","twitter_card":"summary_large_image","twitter_creator":"@buyvpnservice","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"Private Internet Access","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/"},"author":{"name":"Private Internet Access","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/bcf9eb65ae78fade9ba42096f055fb58"},"headline":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit","datePublished":"2021-12-14T20:33:50+00:00","dateModified":"2024-01-24T06:23:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/"},"wordCount":1214,"commentCount":0,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg","articleSection":["Announcements","General Privacy News","VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/","name":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg","datePublished":"2021-12-14T20:33:50+00:00","dateModified":"2024-01-24T06:23:53+00:00","description":"On&nbsp;December 9, 2021, a&nbsp;zero-day vulnerability&nbsp;was&nbsp;disclosed&nbsp;in the open-source Apache library in one of its Java-logging","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/cyber-gefc8bf6b8_1920.jpg","width":1920,"height":1280},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/private-internet-access-vpn-issues-update-to-protect-users-against-apache-log4j-log4shell-exploit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Private Internet Access VPN Issues Update to Protect Users Against Apache Log4j\/Log4Shell Exploit"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/bcf9eb65ae78fade9ba42096f055fb58","name":"Private Internet Access","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f54349bf070d9a32816df7d40c3311a6a4cbfd4c70a3da4e9e678c43b509d02e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f54349bf070d9a32816df7d40c3311a6a4cbfd4c70a3da4e9e678c43b509d02e?s=96&d=mm&r=g","caption":"Private Internet Access"},"sameAs":["https:\/\/www.privateinternetaccess.com"],"url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/private-internet-access-research-team\/"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/42"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=19386"}],"version-history":[{"count":37,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19386\/revisions"}],"predecessor-version":[{"id":19426,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19386\/revisions\/19426"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/19416"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=19386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=19386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=19386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}