当前位置:网站首页>Is log4j vulnerability still widespread?
Is log4j vulnerability still widespread?
2022-07-27 21:46:00 【chenzixia】
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .
Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area 边栏推荐
- Software testing interview question: when does the software testing project start? Why?
- 声扬科技正式上线闻声远程声纹健康回访服务系统!
- 学完4种 Redis 集群方案要多久?我一口气给你说完
- Small change project (two versions) with detailed ideas
- Dual process theory and triple mental model
- zibbix安装部署
- In addition to "adding machines", in fact, your micro service can be optimized like this
- 紫光展锐:2020年将有数十款基于春藤510的5G终端商用
- Basic usage of two-dimensional array
- Commercial delay of self-developed 5g chip? Apple iPhone will adopt Qualcomm 5g chip in the next four years
猜你喜欢
![[2022 Niuke multi School Game 2] k-link with bracket sequence I](/img/95/9d6710bfb7b9282b4a06a5f61a1f08.png)
[2022 Niuke multi School Game 2] k-link with bracket sequence I

Exception -exception

Small change project (two versions) with detailed ideas

8000字讲透OBSA原理与应用实践

Form of objects in memory & memory allocation mechanism

Graphic SQL, this is too vivid!

为什么要使用MQ消息中间件?这几个问题必须拿下

ECCV 2022 | China University of science and Technology & jd.com proposed: data efficient transformer target detector

单核CPU, 1G内存,也能做JVM调优吗?

LInkedList底层源码
随机推荐
day 1 - day 4
Huawei establishes global ecological development department: fully promote HMS global ecological construction
Software testing interview question: what is regression testing?
美国将禁止所有中国企业采购美国芯片?特朗普这样回应
MySQL执行过程及执行顺序
华为成立全球生态发展部:全力推进HMS全球生态建设
聊聊 MySQL 事务二阶段提交
Daily news on July 15, 2022: meta announced the launch of make-a-scene: AI image generation can be controlled based on text and sketches
Software test interview question: does software acceptance test include formal acceptance test, alpha test and beta test?
B站崩了,那晚负责修复的开发人员做了什么?
ADB ~ hide or disable the status bar and virtual keys
Member method and its parameter transmission mechanism
ACM mm 2022 | Zhejiang University proposed: point cloud segmentation, active learning of new SOTA
Enumeration and annotation
内部类(四种内部类详解)
Qmodbus library is used, and it is written as ROS node publishing topic and program cmakelist
Dual process theory and triple mental model
美司法部增加针对华为的指控,包括窃取商业秘密等16项新罪名
LinkedList underlying source code
一文读懂Plato Farm的ePLATO,以及其高溢价缘由