• News/
  • https://www.bleepingcomputer.com/news/security/over-30-percent-of-log4j-apps-use-a-vulnerable-version-of-the-library/

Over 30% of Log4J apps use a vulnerable version of the library

BleepingComputer
·
Bill Toulas
·
Published Dec 10, 2023
·
Updated

Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two years. Log4Shell is an unauthenticated remote code execution (RCE) flaw that allows taking complete control over systems with Log4j 2.0-beta9 and up to 2.15.0. The flaw was discovered as an actively exploited zero-day on December 10, 2021, and its widespread impact, ease of exploitation, and massive security implications acted as an open invitation to threat actors. The circumstance prompted an extensive campaign to notify affected project maintainers and system administrators, but despite numerous warnings, a significant number of organizations continued to use vulnerable versions long after patches became available. Two years after the vulnerability was disclosed and fixes were released, there are plenty of targets still vulnerable to Log4Shell. A report from application security company Veracode, based on data collected between August 15 and November 15, highlights that old problems can persist for an extensive periods. Veracode gathered data for 90 days from 3,866 organizations that use 38,278 applications relying on Log4j with versions between 1.1 and 3.0.0-alpha1. Of those apps, 2.8% use Log4J variants 2.0-beta9 through 2.15.0, which are directly vulnerable to Log4Shell . Another 3.8% use Log4j 2....

Read full article

Affected Software

4 affected components
Apache Log4j=2.0-beta9
Apache Log4j=2.15.0
Apache Log4j=2.17.0
Apache Log4j=1.2.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the alarming statistic that over 30% of applications using the Apache Log4j library are utilizing a vulnerable version.

2

What security implications are discussed?

The article highlights the risks associated with vulnerable versions of Log4j, particularly the critical Log4Shell vulnerability identified as CVE-2021-44228.

3

What products or software are affected?

The affected software includes various versions of Apache Log4j, specifically versions 1.2.x, 2.0-beta9, 2.15.0, and 2.17.0.

4

Why is the Log4Shell vulnerability considered critical?

Log4Shell is deemed critical due to its severity rating and the potential for exploitation in various applications.

5

What percentage of Log4j applications are vulnerable according to the article?

The article states that approximately 38% of applications using Log4j are operating on a vulnerable version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203