Log4Shell, a new vulnerability, is being hailed as one of the biggest cybersecurity weaknesses ever identified. The flaw is based on an open-source logging library that is widely utilised by businesses and even government entities.
According to multiple sources, hackers are already testing exploits for this weakness, which provides them access to an application and might possibly allow them to execute malicious software on a device or servers.
What is the Log4Shell vulnerability?
The vulnerability was discovered on December 9, while other accounts claim it was discovered on December 1st and was highlighted by Chen Zhaojun of Alibaba Cloud Security. The flaw is known as Log4Shell and has the CVE ID CVE-2021-44228 (CVE number is the unique number given to each vulnerability discovered across the world).
The issue affects Log4j 2 versions, a popular logging library used by applications all throughout the globe. Logging allows developers to view all of an application’s activities. This open-source library is used by Apple, Microsoft, and Google, as well as corporate applications from Cisco, Netapp, CloudFare, Amazon, and others.
According to cybersecurity firm Check Point, the open-source Apache Log4j library has over 400,000 downloads from its Github project.
List of Apache projects affected here.
The Dutch National Cyber Security Center (NCSC-NL), which may be accessed here, offers the most comprehensive list of software that is (or is not) impacted by the Log4Shell vulnerability.
At the very least, you’ll be able to double-check any systems or apps you have and apply patches as quickly as feasible!