Log4j

Log4j

Explained: Log4j, A Cyber Flaw That Put The World Into Panic Mode

London: Log4Shell, a new vulnerability, is being hailed as one of the biggest cybersecurity weaknesses ever identified. The flaw is based on an open-source logging library that is widely utilized by businesses and even government entities.

According to multiple sources, hackers are already testing exploits for this weakness, which provides them access to an application and might potentially allow them to run malicious software on a device or servers.

What is Log4J?

Log4j, a key Java-logging framework developed by Apache Software Foundation and is an open-source logging software used in everything from online games to enterprise software and cloud data centres, has security teams all over the world scrambling to fix it.

What exactly is the Log4Shell flaw?

The vulnerability was discovered on December 9, while some claim that the flaw was discovered on December 1 and was highlighted by Chen Zhaojun of Alibaba Cloud Security. The flaw is known as Log4Shell and has the CVE ID CVE-2021-44228 (CVE number is the unique number given to each vulnerability discovered across the world).

 

The issue affects Log4j 2 versions, a popular logging library used by applications all throughout the world. Logging allows developers to see all an application’s activities. According to cybersecurity firm Check Point, the library has had over 400,000 downloads from its GitHub repository.

Why is the Vulnerability Serious?

The flaw is significant because it may allow hackers to take control of Java-based web servers and launch ‘remote code execution (RCE) attacks. To put it straight, the flaw could allow a hacker to take control of a system.

Leave a Reply