Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two years. Log4Shell is an unauthenticated remote code execution (RCE) flaw that allows taking complete control over systems with Log4j 2.0-beta9 and up to 2.15.0. The flaw was discovered as an actively exploited zero-day on December 10, 2021, and its widespread impact, ease of exploitation, and massive security implications acted as an open invitation to threat actors. The circumstance prompted an extensive campaign to notify affected project maintainers and system administrators, but despite numerous warnings, a significant number of organizations continued to use vulnerable versions long after patches became available. Two years after the vulnerability was disclosed and fixes were released, there are plenty of targets still vulnerable to Log4Shell. A report from application security company Veracode, based on data collected between August 15 and November 15, highlights that old problems can persist for an extensive periods. Veracode gathered data for 90 days from 3,866 organizations that use 38,278 applications relying on Log4j with versions between 1.1 and 3.0.0-alpha1. Of those apps, 2.8% use Log4J variants 2.0-beta9 through 2.15.0, which are directly vulnerable to Log4Shell . Another 3.8% use Log4j 2....
Over 30% of Log4J apps use a vulnerable version of the library
BleepingComputer
·Bill Toulas
·Published Dec 10, 2023
·Updated
Affected Software
4 affected components
Apache Log4j=2.0-beta9
Apache Log4j=2.15.0
Apache Log4j=2.17.0
Apache Log4j=1.2.x
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the alarming statistic that over 30% of applications using the Apache Log4j library are utilizing a vulnerable version.
2
What security implications are discussed?
The article highlights the risks associated with vulnerable versions of Log4j, particularly the critical Log4Shell vulnerability identified as CVE-2021-44228.
3
What products or software are affected?
The affected software includes various versions of Apache Log4j, specifically versions 1.2.x, 2.0-beta9, 2.15.0, and 2.17.0.
4
Why is the Log4Shell vulnerability considered critical?
Log4Shell is deemed critical due to its severity rating and the potential for exploitation in various applications.
5
What percentage of Log4j applications are vulnerable according to the article?
The article states that approximately 38% of applications using Log4j are operating on a vulnerable version.