当前位置:网站首页>Is log4j vulnerability still widespread?
Is log4j vulnerability still widespread?
2022-07-27 21:46:00 【chenzixia】
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .
Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area 边栏推荐
- 2021-11-05 understand main method syntax, code block and final keyword
- 自研5G芯片商用推迟?未来4年苹果iPhone都将采用高通5G芯片
- @Autowired注解与@Resource注解的区别
- OPPO造芯计划正式公布:首款芯片或为OPPO M1
- MySQL execution process and order
- 高并发遇到死锁了,如何搞?
- DAY_ 4. Operation -- judge whether there is a certain data in the array -- realize array mapping (enlarge by 10 times) -- insert the array in sequence (modify bugs) -- realize array de duplication
- B站崩了,如果我们是那晚负责修复的开发人员
- 聊聊 MySQL 事务二阶段提交
- QT take out the input box string, lineedit
猜你喜欢

如何实现一个好的知识管理系统?

Box model and element positioning

Pytest failed and rerun

An article takes you into the world of pycharm - stop asking me about pycharm installation and environment configuration!!!

LVS+Keepalived高可用群集

How to realize a good knowledge management system?

B站崩了,那晚负责修复的开发人员做了什么?

腾讯云[HiFlow】| 自动化 -------HiFlow:还在复制粘贴?

看起来是线程池的BUG,但是我认为是源码设计不合理。

In addition to "adding machines", in fact, your micro service can be optimized like this
随机推荐
一篇文章带你走进pycharm的世界----别再问我pycharm的安装和环境配置了!!!
Graphic SQL, this is too vivid!
Idea connects to MySQL database and performs SQL query operations
[2022 Niuke multi School Game 2] k-link with bracket sequence I
CocoaPods 重装
对L1正则化和L2正则化的理解[通俗易懂]
微软商店无法下载应用,VS2019无法下载插件问题解决方案
ECCV 2022 | China University of science and Technology & jd.com proposed: data efficient transformer target detector
Openai issued a document to introduce the latest application of Dall · E 2: fully enter the field of artistic creation and design
内部类(四种内部类详解)
2019q4 memory manufacturers' revenue ranking: Samsung fell 5%, only SK Hynix and micron maintained growth
对象在内存中存在形式&内存分配机制
In addition to "adding machines", in fact, your micro service can be optimized like this
Software test interview question: please say who is the best person to complete these tests, and what is the test?
Nano semiconductor 65W gallium nitride (GAN) scheme was adopted by Xiaomi 10 Pro charger
@Detailed introduction of requestparam annotation
Custom recycleview delete & move animation
软件测试面试题:通过画因果图来写测试用例的步骤为___、___、___、___及把因果图转换为状态图共五个步骤。 利用因果图生成测试用例的基本步骤是?
LinkedList underlying source code
Software test interview question: suppose there is a text box that requires the input of a 10 character postal code, how should the text box be divided into equivalent classes?