当前位置:网站首页>Log4j vulnerability is still widespread and continues to cause impact
Log4j vulnerability is still widespread and continues to cause impact
2022-07-27 21:45:00 【Technical Trivia】
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .
Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area 边栏推荐
- LInkedList底层源码
- After sorting (bubble sorting), learn to continuously update other sorting methods
- 2019Q4内存厂商营收排名:三星下滑5%,仅SK海力士、美光维持增长
- [day_4-review, basic concepts of objects and arrays - 1]
- Software testing interview question: what project documents need to be referred to in designing the system test plan?
- Zibbix installation and deployment
- 软件测试面试题:软件测试项目从什么时候开始?为什么?
- QModbus库使用,并作为ROS节点发布话题及程序CMakelist编写
- XML writing gap animation popupwindow realizes the animation of emergence and exit
- @Autowired注解与@Resource注解的区别
猜你喜欢

Exception -exception

CBAM learning notes

Mobilevit learning notes

day 1 - day 4

@Detailed introduction of requestparam annotation

STL源码剖析

Box model and element positioning

【2022牛客多校第二场】K-Link with Bracket Sequence I

University of Tilburg, Federal University of the Netherlands | neural data to text generation based on small datasets: comparing the added value of two semi supervised learning approvals on top of a l

zibbix安装部署
随机推荐
声扬科技正式上线闻声远程声纹健康回访服务系统!
怎么还有人问 MySQL 是如何归档数据的呢?
For 3nm and below processes, ASML new generation EUV lithography machine exposure
排序(冒泡排序)后面学习持续更新其它排序方法
软件测试面试题:通过画因果图来写测试用例的步骤为___、___、___、___及把因果图转换为状态图共五个步骤。 利用因果图生成测试用例的基本步骤是?
一口气学完 Redis 集群方案
crsctl中,显示的HOME的作用
Who is the sanctity of the six Chinese enterprises newly sanctioned by the United States?
Openai issued a document to introduce the latest application of Dall · E 2: fully enter the field of artistic creation and design
Daily news on July 15, 2022: meta announced the launch of make-a-scene: AI image generation can be controlled based on text and sketches
Software test interview questions: the steps to write test cases by drawing cause and effect diagrams are___ And transforming the cause and effect diagram into a state diagram in five steps. What are
C语言-入门-语法-指针(十二)
MySQL执行过程及执行顺序
Idea connects to MySQL database and performs SQL query operations
V2.X 同步异常,无法云端同步的帖子一大堆,同步又卡又慢
Log4j 漏洞仍普遍存在,并持续造成影响
University of Tilburg, Federal University of the Netherlands | neural data to text generation based on small datasets: comparing the added value of two semi supervised learning approvals on top of a l
In addition to "adding machines", in fact, your micro service can be optimized like this
Box model and element positioning
疫情之下,手机供应链及线下渠道受阻!销量骤降库存严重!