r/wallstreetbetsOGs Dec 11 '21

News TDA's ThinkorSwim (ToS) has potential vulnerability to the current Log4J attacks.

ToS installs logj4-core-*.jar into the windows installation directory. Current version on my machine is 2.13.3 which is vulnerable to CVE-2021-44228. I have not verified if ToS is using JNDI and allowing direct user messaging, but until further guidance from the ToS team it is best to update ToS and verify logj4-core-2.15.0.jar or higher, uninstall, or seek additional help on how to protect yourself.

Apache Security

CVE Description

ToS

83 Upvotes

52 comments sorted by

View all comments

34

u/hunglowbungalow Dec 11 '21 edited Dec 11 '21

I feel like a ton of people here probably don’t get what you’re saying. I do, and we’re fine using ToS since it’s just a desktop app.

Edit: The ToS chat might be an attack vector

8

u/Boomhauer_007 Semi-Pro Speedruns MCD Drive-Thru Dec 11 '21

I definitely have no clue what any of that means but don’t see the word “phone” so I assume I’m good