🔧 Programmierung 🕛 vor 2 Monaten 6 Min Lesezeit CVE-2021-44228
0

NH:STA S01E05 Log4j

Cyber Threat & Vulnerability Dossier CVSS 9.8 CRITICAL (Heuristik) EPSS 92.7%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
Im CVE-Radar öffnen
↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

This post is part of our series on our work for the explains why and how we are contributing to various Open Source projects.



In this episode, we look at migrating test suites, cover that infamous vulnerability and speak to Alba Herrerías Ramírez and Julia Krüger about their work on the project.






Introducing Apache Log4j



would attest to. In 2022, 49% of devs worldwide when surveyed responded that they use Java, and if Log4j is the logging utility of choice, you have a rough idea of how widely deployed this library is. It may not be the only reason you’ve heard of it — but we’ll get to that later.



Logging — documenting events including messages, errors or data in the sequence they occurred in either your operating system or software — is indispensable for devs and QA teams when it comes to understanding actual behaviour and reproducing incidents. When it’s installed on your Java application, Log4j lets you see your app’s processes and get helpful messages about them.



As hinted, if you’re already familiar with Log4j, your first introduction may not have had anything to do with a need to find a logging library for your own project. Log4j was famously the subject of , better known as Log4Shell, was reported in November 2021. It had lain undetected since 2013; long enough for the version with the vulnerability to circulate onto the world’s biggest servers, arguably potentially was successfully founded and funded the following year.






Our contributions



If you’ve been following our work, you’ll know that we’ve gotten quite practiced at joining and assisting teams quickly. To be independent and get up to speed without many resources or help from the core team, we start at the beginning and get the app running locally using contributor instructions. Their docs were excellent. We had no notes.



The Log4j project uses in, we need to get familiar with the idiosyncrasies of the environment that these languages have around them. Refactoring is a great way to get familiar with a project, and .

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
CVE-2024-45058 | portabilis i-educar up to 2.8 Setting educar_usuario_cad.php authorization
1 Quelle
Kompakte 10.000-mAh-Powerbank für weniger als 10 Euro bei Amazon Haul
1 Quelle
Bessere Grafik in Spielen: So steigern Sie die Bildqualität ohne FPS-Verlust
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten NH:STA S01E05 Log4j

Thematisch verwandte Begriffe: NHSTA, S01E05, Log4j · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...