当前位置:网站首页>Is log4j vulnerability still widespread?
Is log4j vulnerability still widespread?
2022-07-27 21:46:00 【chenzixia】
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .
Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area 边栏推荐
- Plato Farm在Elephant Swap上铸造的ePLATO是什么?为何具备高溢价?
- Talk about MySQL transaction two-phase commit
- Simple manual implementation of map
- C语言-入门-语法-指针(十二)
- 最高7.5Gbps!全球首款5nm 5G基带骁龙X60发布:支持聚合全部主要频段!
- 聊聊 MySQL 事务二阶段提交
- @The difference between Autowired annotation and @resource annotation
- Software test interview question: please say who is the best person to complete these tests, and what is the test?
- 腾讯云[HiFlow】| 自动化 -------HiFlow:还在复制粘贴?
- OPPO造芯计划正式公布:首款芯片或为OPPO M1
猜你喜欢

一篇文章带你走进pycharm的世界----别再问我pycharm的安装和环境配置了!!!

Log4j 漏洞仍普遍存在,并持续造成影响

MySQL执行过程及执行顺序

Exception -exception

How to deal with high concurrency deadlock?

CBAM learning notes

MySQL execution process and order

学完4种 Redis 集群方案要多久?我一口气给你说完

Plato Farm在Elephant Swap上铸造的ePLATO是什么?为何具备高溢价?

Comprehensively design an oppe homepage -- Design of selected accessories on the page
随机推荐
Can JVM tuning be done with single core CPU and 1G memory?
软件测试面试题:设计测试用例时应该考虑哪些方面,即不同的测试用例针对那些方面进行测试?
Acwing3715. 最少交换次数(冒泡排序法的模拟思路)
Ziguang zhanrui: dozens of 5g terminals based on chunteng 510 will be commercially available in 2020
B站崩了,那晚负责修复的开发人员做了什么?
美国新宣布制裁的6家中国企业到底是何方神圣?
Software testing interview question: when does the software testing project start? Why?
STL源码剖析
zibbix安装部署
Mobilevit learning notes
数组扩容、排序、嵌套语句应用
深入理解递归的方法调用(含实例迷宫问题、汉诺塔、猴子吃桃、斐波拉契、阶乘))
Will the United States prohibit all Chinese enterprises from purchasing American chips? Trump responded like this
CocoaPods 重装
8000字讲透OBSA原理与应用实践
An article takes you into the world of pycharm - stop asking me about pycharm installation and environment configuration!!!
day 1 - day 4
一文读懂Plato Farm的ePLATO,以及其高溢价缘由
微软商店无法下载应用,VS2019无法下载插件问题解决方案
Custom recycleview delete & move animation