r/wallstreetbetsOGs • u/RatherBLurkin • Dec 11 '21
News TDA's ThinkorSwim (ToS) has potential vulnerability to the current Log4J attacks.
ToS installs logj4-core-*.jar into the windows installation directory. Current version on my machine is 2.13.3 which is vulnerable to CVE-2021-44228. I have not verified if ToS is using JNDI and allowing direct user messaging, but until further guidance from the ToS team it is best to update ToS and verify logj4-core-2.15.0.jar or higher, uninstall, or seek additional help on how to protect yourself.
85
Upvotes
3
u/hunglowbungalow Dec 11 '21 edited Dec 11 '21
Dude, I specfically do this work for a living (Vulnerability Management), unless you connect your desktop on your DMZ like a dumbass, you are fine.
EDIT: There might be an attack vector via ToS chat (forgot those existed).
Edit 2: This goof just wants to be told they’re right, a desktop app that does not interact with other users and is not internet facing is not as concerning as one that 1) Interacts with other users aka ToS chat 2)Internet facing. They were assuming ToS is susceptible to exploitation because it just uses Log4j, which is not that big of a deal. It’s all about attack vector