Log4Shell in December 2021 was patched within days. Finding where Log4j existed in production took much longer.

Most of affected Java projects had Log4j as an indirect dependency bundled with something else, not chosen directly. 80% of those had it five or more levels deep in their dependency tree. Security teams spent the holidays grepping...