当前位置:网站首页>Log4j 漏洞仍普遍存在,并持续造成影响
Log4j 漏洞仍普遍存在,并持续造成影响
2022-07-27 19:10:00 【技术琐事】
Log4j “核弹级” 漏洞 Log4Shell 或许将永远影响世界。
美国国土安全部 (DHS) 网络安全审查委员会 (CSRB) 近日发布了针对去年Log4Shell漏洞的调查报告:
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB 是今年 2 月才由 DHS 成立的机构,职责是调查重大网络安全事件,并提供包含提升国家网络安全建议的报告。CSRB 首次调查的事件正是去年 Log4j 爆发的 “核弹级” 漏洞。

报告指出,虽然没有迹象表明由于 Log4j 漏洞而发生重大网络攻击,但它仍将 “在未来几年内被利用”。国土安全部副部长 Rob Silvers 也表示:“Log4j 漏洞是历史上最严重的软件漏洞之一。”
CSRB 董事会提到,令人惊讶的是,Log4j 漏洞的利用程度低于专家的预期。他们还说到,目前尚未发现针对关键基础设施系统的重大 Log4j 攻击,但有一些网络攻击没有在报告中提到。
董事会表示,未来出现的攻击很可能在很大程度上是因为 Log4j 经常被嵌入到其他软件,由于间接依赖导致企业很难发现在其系统中运行。他们就减轻 Log4j 漏洞的影响以及总体上提升网络安全提出了一些建议,其中包括建议大学和社区学院将网络安全培训作为计算机科学学位和认证计划的必要部分。
根据 sonatype 的统计数据(https://www.sonatype.com/resources/log4j-vulnerability-resource-center),在 Maven Central 上,每个工作日易受攻击的 Log4j 版本仍然有超过 100,000 次的下载量。
最后问一句:你们的 Log4j 漏洞修复了吗?留言区聊聊吧 边栏推荐
- 美国将禁止所有中国企业采购美国芯片?特朗普这样回应
- Up to 7.5gbps! The world's first 5nm 5g baseband snapdragon X60 release: support the aggregation of all major bands!
- 声扬科技正式上线闻声远程声纹健康回访服务系统!
- Qmodbus library is used, and it is written as ROS node publishing topic and program cmakelist
- Analysis of STL source code
- 异常-Exception
- Software testing interview question: what project documents need to be referred to in designing the system test plan?
- Software testing interview question: what aspects should be considered when designing test cases, that is, which aspects should different test cases be tested for?
- 2019Q4内存厂商营收排名:三星下滑5%,仅SK海力士、美光维持增长
- Oppo core making plan officially announced: the first chip or oppo M1
猜你喜欢
![Tencent cloud [hiflow] | automation --------- hiflow: still copying and pasting?](/img/dd/8ee989f5c9db632f78e79425497e71.png)
Tencent cloud [hiflow] | automation --------- hiflow: still copying and pasting?

【2022牛客多校第二场】K-Link with Bracket Sequence I

How to realize a good knowledge management system?

Comprehensively design an oppe homepage -- Design of selected accessories on the page

为什么服务端程序都需要先 listen 一下

Why use MQ message oriented middleware? These questions must be solved

Characteristics of exonuclease in Worthington venom and related literature

Search, insert and delete of hash table

LInkedList底层源码

异常-Exception
随机推荐
@Autowired注解与@Resource注解的区别
Why use MQ message oriented middleware? These questions must be solved
Puzzle (021) eliminate problems
【2022牛客多校第二场】K-Link with Bracket Sequence I
Principle analysis and best practice of guava cache
Comprehensively design an oppe home page -- the style of the search and oper part of the page
Software testing interview question: when does the software testing project start? Why?
2019q4 memory manufacturers' revenue ranking: Samsung fell 5%, only SK Hynix and micron maintained growth
首发展锐5G芯片!纯国产5G手机海信F50曝光:搭载虎贲T710+春藤510
华为成立全球生态发展部:全力推进HMS全球生态建设
Daily Mathematics Series 60: February 29
Report design - how to make your powerbi Kanban brilliant?
Array expansion, sorting, nested statement application
Software test interview question: suppose there is a text box that requires the input of a 10 character postal code, how should the text box be divided into equivalent classes?
Software testing interview question: what aspects should be considered when designing test cases, that is, which aspects should different test cases be tested for?
Characteristics and determination scheme of Worthington mushroom polyphenol oxidase
Instructions - Worthington reverse transcriptase, recombinant HIV testing program
成员方法及其传参机制
Comprehensively design an oppe homepage -- Design of selected accessories on the page
IDEA常用快捷键及设置方法