Intelligence View
A Review of Log4Shell Detection Methods
Ever since the public exploit of the Log4Shell remote code execution (RCE) vulnerability became known on December 10, 2021, security teams have been scrambling to understand the risk to their environments. Part of that scramble has been to …
Software Composition Analysis (SCA)
SCA tools are focused on risks associated with third-party libraries. As such, they are well-suited to identify the presence of vulnerable log4j-core components in Java applications and other Java codebases. It's important that the SCA tool pinpoints and reports the exact version that is being used as there has been a flurry of releases of log4j-core in the past two weeks. As of this writing, 2.17 is considered the only fully safe…
SOCIAL SHARE CARD GENERATOR