当前位置:网站首页>Log4j vulnerability is still widespread and continues to cause impact
Log4j vulnerability is still widespread and continues to cause impact
2022-07-27 21:45:00 【Technical Trivia】
Log4j “ Nuclear grade ” Loophole Log4Shell May affect the world forever .
Department of homeland security (DHS) Network Security Review Committee (CSRB) Recently released for last year Log4Shell Vulnerability Investigation Report :
https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf
CSRB This year 2 The month is only by DHS Established institution , Responsibility is to investigate major network security incidents , And provide a report containing recommendations to improve National Cybersecurity .CSRB The first incident investigated was last year Log4j Explosive “ Nuclear grade ” Loophole .

According to the report , Although there is no indication that due to Log4j Vulnerabilities and major network attacks , But it will still be “ Be used in the next few years ”. Deputy Secretary of Homeland Security Rob Silvers Also said :“Log4j Vulnerability is one of the most serious software vulnerabilities in history .”
CSRB The board mentioned , It's amazing ,Log4j The degree of vulnerability utilization is lower than experts' expectation . They also said , At present, there is no significant... For key infrastructure systems Log4j attack , But there are some cyber attacks that are not mentioned in the report .
The board said , Future attacks are likely to be largely due to Log4j Often embedded in other software , Due to indirect dependence, it is difficult for enterprises to find running in their systems . They lighten Log4j The impact of vulnerabilities and the overall improvement of network security put forward some suggestions , This includes advising universities and community colleges to make cybersecurity training an integral part of their computer science degree and certification programs .
according to sonatype Statistical data (https://www.sonatype.com/resources/log4j-vulnerability-resource-center), stay Maven Central On , Vulnerable every working day Log4j There are still more than 100,000 Number of downloads per time .
Finally, ask : Yours Log4j Has the vulnerability been fixed ? Let's talk in the message area 边栏推荐
- XML writing gap animation popupwindow realizes the animation of emergence and exit
- 2019Q4内存厂商营收排名:三星下滑5%,仅SK海力士、美光维持增长
- Daily news on July 15, 2022: meta announced the launch of make-a-scene: AI image generation can be controlled based on text and sketches
- 零钱通项目(两个版本)含思路详解
- Unit-- read Excel
- Excalidraw: an easy-to-use online, free "hand drawn" virtual whiteboard tool
- day 1 - day 4
- LVS+Keepalived高可用群集
- Software testing interview question: what is the focus of unit testing, integration testing, and system testing?
- Plato Farm在Elephant Swap上铸造的ePLATO是什么?为何具备高溢价?
猜你喜欢

Box model and element positioning

Small change project (two versions) with detailed ideas

聊聊 MySQL 事务二阶段提交

IDEA连接MySQL数据库并执行SQL查询操作

一篇文章带你走进pycharm的世界----别再问我pycharm的安装和环境配置了!!!

An article takes you into the world of pycharm - stop asking me about pycharm installation and environment configuration!!!

对象在内存中存在形式&内存分配机制

Comprehensively design an oppe home page -- the style of the search and oper part of the page

Common shortcut keys and setting methods of idea

ACM mm 2022 | Zhejiang University proposed: point cloud segmentation, active learning of new SOTA
随机推荐
STL源码剖析
@Autowired注解与@Resource注解的区别
Daily news on July 15, 2022: meta announced the launch of make-a-scene: AI image generation can be controlled based on text and sketches
Acwing3715. 最少交换次数(冒泡排序法的模拟思路)
Software testing interview question: what is regression testing?
B站崩了,那晚负责修复的开发人员做了什么?
Idea connects to MySQL database and performs SQL query operations
软件测试面试题:在windows下保存一个文本文件时会弹出保存对话框,如果为文件名建立测试用例,等价类应该怎样划分?
MySQL execution process and order
8000字讲透OBSA原理与应用实践
Unit-- read Excel
Instructions - Worthington reverse transcriptase, recombinant HIV testing program
JVM-内存模型 面试总结
ACM mm 2022 | Zhejiang University proposed: point cloud segmentation, active learning of new SOTA
腾讯云[HiFlow】| 自动化 -------HiFlow:还在复制粘贴?
@The difference between Autowired annotation and @resource annotation
软件测试面试题:请说出这些测试最好由那些人员完成,测试的是什么?
Pytest failed and rerun
QT take out the input box string, lineedit
Acwing3715. Minimum exchange times (simulation idea of bubble sorting method)