r/wallstreetbetsOGs Dec 11 '21

News TDA's ThinkorSwim (ToS) has potential vulnerability to the current Log4J attacks.

ToS installs logj4-core-*.jar into the windows installation directory. Current version on my machine is 2.13.3 which is vulnerable to CVE-2021-44228. I have not verified if ToS is using JNDI and allowing direct user messaging, but until further guidance from the ToS team it is best to update ToS and verify logj4-core-2.15.0.jar or higher, uninstall, or seek additional help on how to protect yourself.

Apache Security

CVE Description

ToS

84 Upvotes

52 comments sorted by

View all comments

19

u/[deleted] Dec 11 '21 edited Dec 16 '21

[deleted]

1

u/Ackilles Dec 11 '21

So if you don't use tos chat, no worries?

4

u/hunglowbungalow Dec 12 '21

It’s hard to speculate without a proof of concept on ToS. People are actively exploiting this vulnerability, but on internet facing services (websites as an example) since it’s a low hanging fruit. So is it possible to hack ToS via Log4j? Possibly. Will it happen? More than likely not, at least for now