Log4Shell Is Almost Five Years Old. Most Teams Still Can't Answer "What's In Our Software?"
Apache disclosed Log4Shell on December 9–10, 2021. As I write this, that's closing in on five years ago — long enough that it should be ancient history, a war story security teams tell new hires. It isn't. Talk to anyone who was on call that week and you'll hear the same detail every time: patching wasn't the hard part. Alibaba's Chen Zhaojun had reported the flaw responsibly on November 24; within hours of the public disclosure, mass scanning and exploitation were already underway, and CISA and the wider Joint Cyber Defense Collaborative were coordinating an emergency response. The vulnerability itself scored a maximum 10.0 on the CVSS scale. Early U.S. government estimates, reported by the Wall Street Journal, put the number of potentially exposed devices in the hundreds of millions. And the hardest part, for most organizations, wasn't applying the fix once they knew where it was needed. It was...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE