Log4Shell update: second Log4j vulnerability published
1–10 of 289 posts
Re: Log4Shell update: second Log4j vulnerability published
#2If you've patched against Log4Shell, please read this to make sure you're not still vulnerable to this 2nd CVE. In some cases, you're still vulnerable depending on how you patched.
In response to this, Apache published log4j 2.16.0 to mitigate the bugs in prior versions (including 2.15.0, the release that was supposed to mitigate Log4Shell initially)
Re: Log4Shell update: second Log4j vulnerability published
#3The annoying thing is, since it is evolving and attacks are spreading (and it has rightly gotten the attention of nearly everyone's IT department), we're hitting a stage where almost every customer is emailing daily asking for updates on mitigations based on evolving CVE discussions.
I'd rather people be over-vigilant rather than pass on it, but mitigation is taking a back seat to having to re-read and re-evaluate things multiple times per day, and communicate a lot more than usual to assuage people's nerves.
Re: Log4Shell update: second Log4j vulnerability published
#4Re: Log4Shell update: second Log4j vulnerability published
#5Re: Log4Shell update: second Log4j vulnerability published
#6Re: Log4Shell update: second Log4j vulnerability published
#7Re: Log4Shell update: second Log4j vulnerability published
#8Re: Log4Shell update: second Log4j vulnerability published
#9Re: Log4Shell update: second Log4j vulnerability published
#10My kids are tremendously disappointed that the Minecraft server is not coming back up in the near future.