Marcel SIneM(S)US · @simsus
177 followers · 3413 posts · Server social.tchncs.de
Christoph Matthies :verified: · @chrisma
116 followers · 1591 posts · Server mstdn.social

RT @grobmeier@twitter.com

2 in version 2.17.1 is probably the most reviewed logging library ever. When you are concerned about software security use the moste recent version of . Big team. Many reviewers. Stay safe (and sorry for the issue before)

🐦🔗: twitter.com/grobmeier/status/1

#Java #log4j2 #log4j

Last updated 4 years ago

I have no hot takes about the recent log4j2 vulnerability.

It just was a lot of work to update all the container images involved in a microservices architecture.
This is one aspect of microservices that I never really considered before this happened.

Meanwhile, maintainers of monolithic Java applications and those that used the OS dependency didn't have as much work to do.

#log4j2 #microservices

Last updated 4 years ago

· @grayrecord
2 followers · 223 posts · Server pawoo.net

log4jの脆弱性について ezoeryou.github.io/blog/articl 今のところ日本語ではこれが一番わかりやすい。

#log4j2 #log4j #Log4Shell

Last updated 4 years ago

AiRolG · @airolgloria
15 followers · 406 posts · Server mastodon.online

a 0-day exploit in the popular Java logging library log4j was discovered that results in Remote Code Execution (RCE) by logging a certain string.
* the impact of the exploit (full server control)
* JDK versions greater than 6u211, 7u201, 8u191, and 11.0.1 are safe
* 2.0 <= Apache log4j <= 2.14.1 are in trouble


lunasec.io/docs/blog/log4j-zer

#update #jndi #rce #apache #p0rz9 #day2 #Java #log4j2

Last updated 4 years ago